Quantum ransomware is a double-extortion ransomware operation associated with the post-Conti Russian-speaking cybercrime ecosystem. It encrypts victim environments and exfiltrates data to pressure victims with threatened publication or sale of stolen information. Quantum was active against mid-market and larger enterprises and has been associated with domain-wide ransomware deployment following prolonged intrusions involving reconnaissance, lateral movement, remote-access tooling, and data theft. Reporting on the Conti ecosystem describes Quantum as a successor subgroup formed after Conti’s 2022 breakup; Quantum subsequently rebranded as Royal, which later became BlackSuit. Quantum has also been linked to ransomware affiliate and infrastructure overlap involving Conti-associated actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike, and the Ryuk, Conti, and Quantum ransomware strains.
Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond... In the academic literature, these are called 'man-in-the-middle' attacks... More specifically, they are examples of 'man-on-the-side' attacks.
By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond... In the academic literature, these are called 'man-in-the-middle' attacks... More specifically, they are examples of 'man-on-the-side' attacks.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family listed among strains associated through transactions with Stern.
A ransomware family/group described as a Conti successor that rebranded first to Royal and later to BlackSuit.
Referenced as a known malware family based on labels found on related malicious files in VirusTotal.
A ransomware subgroup/brand that emerged from Conti and then quickly rebranded to Royal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.