Conti emerged as one of the most active ransomware-as-a-service operations, using spearphishing, exposed RDP, and loaders such as BazarLoader, TrickBot, IceID, and Emotet to gain access before deploying Cobalt Strike, stealing data, and encrypting systems across networks. Security reporting tied the group to more than 400 attacks globally, with victims concentrated in North America and Europe, and described technical tradecraft including credential attacks, shadow copy deletion, service termination, remote SMB encryption, and ransom notes named CONTI_README.txt. In industrial environments, Dragos said ransomware became the leading cause of compromises in 2021, with Conti and LockBit 2.0 accounting for more than half of observed incidents, while suspected Conti-linked activity was later detected at major automotive manufacturers and suppliers in North America and Japan.
Leaked internal chats, source code, and infrastructure data exposed Conti as a highly organized criminal business rather than a loose affiliate network. Researchers identified a core group of roughly 44 members within a wider set of 442 chat handles, with dedicated teams for coding, reverse engineering, OSINT, HR, payroll, and a "Fire Team" that conducted victim research, built phishing phone and email scripts, and helped pressure victims during ransom negotiations using tools such as Shodan, SpiderFoot, SignalHire, and ZoomInfo. The group’s impact was illustrated by the attack on Ireland’s Health Service Executive, where about 80% of IT systems were encrypted, roughly 700 GB of data was stolen, and healthcare services were disrupted nationwide before Conti offered a free decryptor while still demanding a $20 million ransom and threatening to leak the data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Dragos reported sustained communications from December 2021 through March 2022 between Emotet command-and-control infrastructure and multiple automotive-sector organizations in North America and Japan, which it assessed were likely linked to Conti operations.
Arctic Wolf said the Conti ransomware group posted a public statement supporting Russia, a move that preceded the major leak of its internal data.
On February 3, 2022, the U.S. Department of Health and Human Services published a threat brief describing the 2021 Conti attack on Ireland's Health Service Executive, including that 80% of its IT systems were encrypted and about 700 GB of data was stolen.
Qualys said CISA and the FBI issued a warning in September 2021 stating they had observed Conti used in more than 400 cyberattacks globally, concentrated in North America and Europe.
The DFIR Report described an early-August 2021 intrusion in which attackers used phishing-delivered BazarLoader, Cobalt Strike, lateral movement, and rclone exfiltration to MEGA before deploying Conti ransomware on day five to encrypt most domain-joined systems. The report also published technical indicators and detection content, including C2 infrastructure, hashes, JA3/JA3s, and Suricata, Sigma, and YARA rules.
Leaked Conti information analyzed by Intel 471 showed that an internal division called the Fire Team started in July 2021 to create phishing call cover stories and randomize spam letters for prospective victims.
SophosLabs added a "Ransomware-Conti.csv" file to its IoC repository with domains, IPs, URL paths, and file hashes associated with Conti activity, including Cobalt Strike infrastructure and a hash for the conti.exe payload. The IoC set was tied to a Sophos report on Conti ransomware.
Qualys reported that the Conti ransomware-as-a-service operation was first detected in December 2019 and rapidly grew after its emergence, displacing other tools such as Ryuk.
Intel 471 analyzed leaked Conti communications and described the Fire Team as an internal business-intelligence and sales-like unit that gathered reconnaissance, developed phishing scripts, and participated in ransom negotiations.
Arctic Wolf published analysis of the leaked Conti materials, concluding the group operated as a structured organization with a core group of about 44 members inside a broader network of 442 chat handles.
After Conti's pro-Russia statement, an actor using the @ContiLeaks handle published leaked internal Jabber chats, infrastructure details, internal documents, and source code, accompanied by the phrase "Glory to Ukraine."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
intel471.com
Open sourcearcticwolf.com
Open sourcedragos.com
Open sourcebleepingcomputer.com
Open sourcecarbonblack.com
Open sourcehub.dragos.com
Open sourcecybereason.com
Open sourcecybleinc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.