contfr

Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:54:17

Context

Launched around September 2024, ContFR is a French-speaking RaaS that uses a Tor-hosted platform to provide ransomware embedded in PDF files (targeting both Windows and macOS). The group offers a tiered subscription model—“TEST,” “BASIC,” and “ELITE”—allowing affiliates varying degrees of customization, offline capability, and support based on the package purchased. As of the latest reporting, no victims are publicly listed, though data leak publications likely require a subscription to access. The operation suggests an organized, business‑like structure, distinct from opportunistic one‑off strains.

Reports & references

  • ransomlook.io — Contfr (report)
  • cyjax.com — Contfraversy In Ransomland Tor Based Site Emerges For New French Speaking Raas Operation Contfr (report)

External references