Conti
MITRE ATT&CK: S0575 View on attack.mitre.org
Aliases: Conti
- First seen
- 2019-12-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 114 (109 malicious)
- Last IoC activity
- 2026-09-01 23:56:54
- Profile updated
- 2026-07-07 12:37:42
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services technology-and-telecommunications
Targeted regions: country_code:us country_code:ca
Context
Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.
Recent IoC activity
110 malicious indicators in Maltiverse are attributed to Conti (S0575). The 20 most recently updated:
Detection coverage
- 6 YARA rules
- 297 Sigma rules
Malware & tools used
- Network Share Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Service Stop (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Remote System Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Taint Shared Content (attack-pattern)
- Windows Command Shell (attack-pattern)
- Process Discovery (attack-pattern)
- Native API (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
Used by threat actors
- Wizard Spider (threat-actor)
- C0015 (campaign)
Detection rules
- TRELLIX_ARC_Ransom_Conti (yara-rule)
- ARKBIRD_SOLG_RAN_Conti_May_2021_2 (yara-rule)
- ARKBIRD_SOLG_RAN_Conti_Dec_2021_1 (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Conticrypter (yara-rule)
- CAPE_Conti (yara-rule)
- MALPEDIA_Win_Conti_Auto (yara-rule)
Related threat objects
- BlackByte (malware)
- QuantumLocker (malware)
- BlackBasta (malware)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- pwc.com — Yir Cyber Threats Annex Download (report)
- prodaft.com — Wizardspider Tlpwhite V.1.4 (report)
- analyst1.com — Ransom Mafia Analysis Of The World%E2%80%99S First Ransomware Cartel (report)
- CrowdStrike — Report2021Gtr (report)
- analyst1.com — Ransom Mafia Analysis Of The Worlds First Ransomware Cartel (report)
- blog.google — Exposing Initial Access Broker Ties Conti (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- CrowdStrike — Wizard Spider Adversary Update (report)
- blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
- Microsoft — Re54L7V (report)
- CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
- domaintools.com — The Most Prolific Ransomware Families A Defenders Guide (report)
- cisoclub.ru — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- cti-league.com — Cti League Darknet Report 2021 (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- ke-la.com — To Attack Or Not To Attack Targeting The Healthcare Sector In The Underground Ecosystem (report)
- ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
- krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- vulnerability.ch — Ransomware And Date Leak Site Publication Time Analysis (report)
- web.archive.org — Otchet Kompanii Group Ib Ransomware Uncovered 2020 2021 (report)
- coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)