Conti is a Russian-speaking ransomware family and associated ransomware-as-a-service operation that became one of the most prolific extortion threats of the early 2020s. It is closely linked to the TrickBot and Wizard Spider cybercrime ecosystem, and reporting has identified senior figures from that ecosystem as key Conti operators. The group’s internal leaks exposed a structured, enterprise-like organization with defined roles, manuals, training materials, operational procedures, and centralized management of affiliates and intrusion workflows. After the operation’s collapse in 2022 following major internal leaks, members and tradecraft dispersed into other ransomware groups, and leaked Conti code continued to influence later ransomware families and variants.
Conti primarily targeted Windows environments and was used in high-impact attacks across many sectors, including healthcare, government, financial services, and other large enterprises. The malware is designed to encrypt victim files and support extortion operations, and the broader Conti intrusion lifecycle commonly involved network reconnaissance, credential abuse, lateral movement, and data theft prior to encryption. Public reporting and derivative-family analysis also associate Conti-based code with capabilities such as process and service termination to remove obstacles to encryption, impairment of security controls, recovery inhibition, event log clearing, network-share encryption, and multi-threaded file encryption. Conti operators followed repeatable playbooks rather than highly variable tradecraft, which made the group notable both for operational scale and for the consistency of its procedures.
Conti has strong historical ties to Ryuk through personnel overlap, with many Ryuk members later joining the Conti operation. The family also served as a code lineage for later ransomware development, with multiple subsequent actors and strains reported to have reused or modified leaked Conti source code. Conti is widely regarded as a landmark ransomware operation because of its scale, organizational maturity, and the unusually detailed visibility provided by leaked chats and source code into the workings of a major cybercriminal enterprise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Log4Shell (CVE-2021-44228) Disclosed on December 9th, 2021, Log4Shell (CVE-2021-44228) is one of the more memorable recent supply chain vulnerabilities with widespread industry impact. This was a critical remote code execution vulnerability in Apache Log4J, a Java logging library utility used by many applications.
Activists have reportedly leaked the contents of internal chats from the Russia-affiliated Conti ransomware gang... Both Conti and another criminal crew called Karma hit the unidentified org through the ProxyShell exploit... Conti was deploying its own malware.
21 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Devman, a ransomware operator believed to be based in Russia and utilizing code derived from the leaked Conti source.
The sample analyzed in this report was identified as DragonForce ransomware developed based on Conti ransomware.
A longtime former member of Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022, pleaded guilty ... The defendant and his conspirators used the Conti ransomware to terrorize people and businesses in the United States and around the world, causing millions of dollars in damage.
Waseem Ahmed, head of engineering at Secure.com, explained that SGR is a Conti offshoot now running pure data-theft extortion.
Waseem Ahmed, head of engineering at Secure.com, explained that SGR is a Conti offshoot now running pure data-theft extortion.
The crypto-locking malware first emerged around the middle of 2018 and seemed to have its heyday largely in 2019, before rebranding as Conti around May 2020, and appearing to merge with TrickBot - aka Wizard Spider - by the end of 2021.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Some ransomware operators do not allow targeting (encrypting and exfiltrating data) of non-profit organizations, healthcare, and government entities...
According to prosecutors, Lytvynenko and his co-conspirators deployed Conti ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments.
Court filings allege the conspirators hacked into victims’ computers and networks, encrypted data, and demanded a ransom to restore the victims’ access to their files and to avoid public disclosure of the stolen information.
On top of client applications such as those provided by Mega, many ransomware families may use other software or built-in operating system utilities to exfiltrate data. We’ll use Mega as the example here... you can look for execution of any process that is not chrome.exe ... initiating a network connection to the domains mega.io or mega.co.nz .
Trickbot is a cybercriminal group that has conducted ransomware campaigns across essential services including healthcare and banking. | The EU designated Vitaly Nikolayevich Kovalev, also known as “Stern,” administrator of the Trickbot ransomware operations who has received more than $300 million in ransom payments.
The RstrtMgr DLL (Restart Manager) is being loaded by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them... It could also be used for anti-analysis purposes by shutting down specific processes.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
The ransomware attack has prevented the government from effectively collecting taxes, and some public employees’ salaries are either being overpaid or underpaid, Chaves said.
He analyzed stolen data and used sensitive information to intensify extortion tactics. When the ransom demand was not met, he allegedly encouraged co-conspirators to leak or sell the data. Court documents reveal he distributed a bulk set of sensitive records to hundreds of patients, aiming to amplify fear and force compliance.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named ransomware family that DevMan explicitly claimed to have worked with.
A prolific ransomware family/group referenced as a major early-2020s operator disrupted by law enforcement action.
Ransomware group/family referenced in connection with Vitaly Kovalev's alleged leadership role.
A ransomware family described as one of the notorious strains linked to the Trickbot ecosystem and Stern’s operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.