Conti was a major Russian-speaking ransomware operation active in the early 2020s and widely regarded as one of the most prolific and organized cybercriminal groups of its era. It operated as a ransomware-as-a-service and affiliate-driven enterprise with a structured, corporate-style model that included administrators, operators, negotiators, technical staff, documented procedures, training materials, and salary-like compensation. The group conducted double-extortion campaigns, combining network-wide encryption with data theft and threats to publish stolen information. Conti targeted a broad range of sectors worldwide, including healthcare, government, education, manufacturing, and other businesses, with significant impact in the United States and Europe. It was associated with large-scale intrusions against enterprises, hospitals, and public-sector organizations, and it was among the ransomware groups most frequently observed exploiting major vulnerabilities such as Log4Shell during opportunistic intrusion waves. Operationally, Conti relied on repeatable playbooks rather than constantly changing tradecraft. Reporting and later leaks exposed mature intrusion workflows involving initial access through phishing, exposed remote services, purchased access, and exploitation of vulnerabilities; followed by reconnaissance, credential theft, lateral movement, privilege escalation, backup disruption, data exfiltration, and rapid ransomware deployment. The group and its operators have been associated with common enterprise attack tooling and administrative utilities, including PsExec for propagation. Conti’s leaked internal materials also showed strong procedural discipline, chain of command, and similarities to Ryuk-era tradecraft. Conti is closely linked to the broader Wizard Spider and TrickBot cybercrime ecosystem, and many researchers assess it as an evolution or successor formation involving personnel from Ryuk operations. Numerous Ryuk members later joined Conti, and after Conti’s collapse in 2022, personnel and expertise appear to have dispersed into successor or related groups. Multiple later ransomware operations, including Black Basta, Akira, and Silent Ransom Group, have been discussed as containing former Conti members, inheriting elements of its playbooks, or showing code and operational overlap. The group became especially notable in 2022 after publicly expressing support for the Russian government following the invasion of Ukraine, which triggered internal dissent and major leaks of chat logs and internal documentation. Those leaks provided unusually detailed visibility into Conti’s internal management, technical operations, negotiation practices, and infrastructure administration, and they contributed to the group’s implosion and reorganization. The disruption of Conti in 2022 coincided with a broader temporary decline in confirmed ransomware activity as actors regrouped around the Russia-Ukraine war. Known aliases include Conti Gang and Conti Ransomware Group. Individuals publicly linked to leadership or senior operational roles include aliases such as Bentley, and sanctions reporting has tied alleged leader Vitaly Nikolayevich Kovalev to Conti as well as to TrickBot and Wizard Spider. Conti is best understood not as a single malware strain alone, but as a large, disciplined criminal organization whose personnel, methods, and ecosystem influence persisted well beyond the formal brand’s demise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor/ransomware operation that DevMan claimed to have worked with previously.
Prolific ransomware group in the early 2020s responsible for numerous attacks across business, healthcare, and government sectors.
Related Articles: Ukrainian national pleads guilty to role in Conti ransomware operation
Ransomware criminal organization whose leaked internal data highlighted Vitaly Kovalev's leadership role.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.