Quantum is a Windows ransomware family associated with the post-Conti cybercrime ecosystem. It emerged as one of the successor brands used by actors linked to Conti after that syndicate fragmented in 2022, and it is widely reported to have later rebranded into Royal and subsequently BlackSuit. Quantum has been referenced alongside other Conti-derived or affiliated operations in financially motivated intrusions targeting enterprises and critical-sector organizations.
Observed Quantum intrusions follow a conventional big-game ransomware pattern centered on enterprise compromise, lateral movement, data theft, and domain-wide encryption. In documented cases, operators conducted multi-day hands-on-keyboard activity after initial access, used post-exploitation tooling such as Cobalt Strike, leveraged remote administration software for command and control, exfiltrated victim data, and then deployed the ransomware broadly across the environment. Remote execution and propagation have been observed via administrative mechanisms such as WMI and PsExec, consistent with mass deployment across Windows domains.
Quantum has been linked to intrusion chains in which initial access was obtained through phishing-delivered malware, including Emotet, and to broader ransomware ecosystems that also relied on loaders such as Qakbot and BumbleBee. Reporting also places Quantum among ransomware brands used by financially motivated actors such as Vanilla Tempest, and among strains connected through transactions and personnel overlap to senior TrickBot and Conti figures. The family has also been cited in discussions of re-extortion behavior among ransomware operations targeting mid-market and larger enterprises.
At high confidence, Quantum should be understood as a Conti-lineage ransomware brand used in double-extortion-style enterprise attacks against Windows environments, with capabilities including data exfiltration, lateral movement, post-exploitation activity, and impact through large-scale encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond... In the academic literature, these are called 'man-in-the-middle' attacks... More specifically, they are examples of 'man-on-the-side' attacks.
By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond... In the academic literature, these are called 'man-in-the-middle' attacks... More specifically, they are examples of 'man-on-the-side' attacks.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family listed among strains associated through transactions with Stern.
A ransomware family/group described as a Conti successor that rebranded first to Royal and later to BlackSuit.
Referenced as a known malware family based on labels found on related malicious files in VirusTotal.
A ransomware subgroup/brand that emerged from Conti and then quickly rebranded to Royal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.