Conti was a highly prolific Russian-speaking ransomware operation active primarily from 2020 until its collapse in 2022. It is widely associated with the broader TrickBot and Wizard Spider cybercrime ecosystem and is assessed to have operated as a mature ransomware enterprise with corporate-style management, including administrators, developers, negotiators, middle management, and human-resources-like functions. The group publicly aligned itself with the Russian government after the 2022 invasion of Ukraine, a move that triggered major internal leaks and accelerated its disintegration. Conti is best understood as both a ransomware brand and a central node in a wider criminal network whose personnel later dispersed into successor and affiliated operations. Conti conducted large-scale double-extortion campaigns, combining network intrusion, data theft, file encryption, and ransom negotiations. It targeted more than 1,000 victims worldwide between 2020 and 2022, including healthcare organizations, government entities, educational institutions, and private-sector businesses across dozens of countries. The operation was among the most financially successful ransomware groups of its era, with U.S. authorities estimating at least $150 million in ransom proceeds by early 2022. The group was known for disciplined post-compromise tradecraft and rapid lateral movement. Reported techniques included use of stolen or purchased access, deployment of loader malware, credential theft, privilege escalation, remote administration tooling, SMB-based propagation, PsExec, RDP, and broad use of native Windows administration mechanisms. Conti and its ecosystem also showed capability against virtualized environments, including development of Linux and ESXi-focused tooling. Its operations were supported by a broader malware stack historically linked to TrickBot-related families and precursor access operations. Conti’s leaked internal communications exposed unusually detailed insight into ransomware business operations, including negotiation practices, internal hierarchy, infrastructure management, and affiliate-style coordination. Those leaks also reinforced the view that Conti functioned less like an ad hoc gang and more like an organized criminal syndicate with specialized roles and repeatable playbooks. After the brand imploded in 2022, former members and sub-teams were widely assessed to have reconstituted across multiple ransomware and extortion operations. Groups and clusters repeatedly linked to former Conti personnel or tradecraft include Black Basta, Royal, BlackSuit, 3AM, Akira, and the Silent Ransom Group, among others. Many Ryuk-associated actors are also understood to have transitioned into Conti earlier, making Conti a key bridge between earlier Ryuk activity and later ransomware reorganizations. Because of this fragmentation, Conti’s legacy persists through successor crews, shared operators, reused procedures, and overlapping tooling rather than through continued operation under the original name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a later ransomware operation joined by many former Ryuk members.
Now-defunct ransomware operation whose shutdown is associated in the report with the 2022 decline in confirmed ransomware attacks.
Referenced as a prior ransomware group whose leaked communications revealed behind-the-scenes extortion negotiations.
Referenced as the parent/offshoot lineage for Silent Ransom and as a source of leaked chats used to study extortion negotiations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.