Conti

MITRE ATT&CK: S0575 View on attack.mitre.org

Aliases: Conti

First seen
2019-12-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
114 (109 malicious)
Last IoC activity
2026-09-01 23:56:54
Profile updated
2026-07-07 12:37:42

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services technology-and-telecommunications

Targeted regions: country_code:us country_code:ca

Context

Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.

Recent IoC activity

110 malicious indicators in Maltiverse are attributed to Conti (S0575). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample hook.jar 2026-09-02 2
file sample ebeca2df24a55c629cf0ce0d4b703ed632819d8ac101b1b930ec666760036124 2026-08-29 2
file sample d21c71a090cd6759efc1f258b4d087e82c281ce65a9d76f20a24857901e694fc 2026-08-25 2
file sample 2026-08-23_258085d8596b9310bd823cbf7ec58e4b_amadey_conti_elex 2026-08-24 1
file sample 2026-08-23_55cf778512e989699d84ae821b7d9f01_amadey_conti_elex 2026-08-24 1
file sample 2026-08-23_6f0023fa9fbd687246fbcf65fb5c45b1_amadey_conti_elex 2026-08-24 1
file sample 2026-08-23_7fb0e3345df3cfcf87fc85b345364ce3_amadey_conti_elex 2026-08-24 1
file sample 2026-08-23_bee9004a3527c43169fea794f8f16c57_bitrat_conti_elex_remcos 2026-08-23 1
file sample 2fc6d7df9252b1e2c4eb3ad7d0d29c188d87548127c44cebc40db9abe8e5aa35.bin 2026-08-16 3
file sample ed03ec3c36db5fafd7285eb732333e5574d2bfa59efb19fe21c07627af9a5d6b 2026-08-12 1
file sample e872de0a4a063c49348d002a17f719ded0b39ac01edea2fc4383e737959ec037 2026-08-12 1
file sample 085e87a6694edafd9a614a1f1143eb85233c04afbe9f84c89ebe5aebcd14546f 2026-08-10 1
URL https://contirecovery.info 2026-07-31 1
file sample locker.exe 2026-07-27 1
file sample 1cdfa75b103f4b3218a9f6ddec137a5438c5e6571151d0979c60d96dfbbf9231 2026-07-26 1
file sample sub_f848c62dbc91.bin 2026-07-26 1
file sample 95776f31cbcac08eb3f3e9235d07513a6d7a6bf9f1b7f3d400b2cf0afdb088a7.elf 2026-07-20 2
file sample fe6e84192da5c0210d4bd51e809792b28e60edb337917f903a7e9a31bc40cf86.bin.sample 2026-07-18 2
file sample c503289716c5b6c581a99953a90bcc2b93f14353658bd931aa83fd55d02624f1.exe 2026-07-11 2
file sample demo.exe 2026-07-03 2

Detection coverage

  • 6 YARA rules
  • 297 Sigma rules

Malware & tools used

  • Network Share Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Service Stop (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Taint Shared Content (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Process Discovery (attack-pattern)
  • Native API (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)

Used by threat actors

Detection rules

  • TRELLIX_ARC_Ransom_Conti (yara-rule)
  • ARKBIRD_SOLG_RAN_Conti_May_2021_2 (yara-rule)
  • ARKBIRD_SOLG_RAN_Conti_Dec_2021_1 (yara-rule)
  • SIGNATURE_BASE_MAL_RANSOM_Conticrypter (yara-rule)
  • CAPE_Conti (yara-rule)
  • MALPEDIA_Win_Conti_Auto (yara-rule)

Related threat objects

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • pwc.com — Yir Cyber Threats Annex Download (report)
  • prodaft.com — Wizardspider Tlpwhite V.1.4 (report)
  • analyst1.com — Ransom Mafia Analysis Of The World%E2%80%99S First Ransomware Cartel (report)
  • CrowdStrike — Report2021Gtr (report)
  • analyst1.com — Ransom Mafia Analysis Of The Worlds First Ransomware Cartel (report)
  • blog.google — Exposing Initial Access Broker Ties Conti (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • CrowdStrike — Wizard Spider Adversary Update (report)
  • blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
  • Microsoft — Re54L7V (report)
  • CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
  • domaintools.com — The Most Prolific Ransomware Families A Defenders Guide (report)
  • cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • cti-league.com — Cti League Darknet Report 2021 (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • ke-la.com — To Attack Or Not To Attack Targeting The Healthcare Sector In The Underground Ecosystem (report)
  • ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
  • krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
  • web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
  • coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)

External references