contfr
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:54:17
Context
Launched around September 2024, ContFR is a French-speaking RaaS that uses a Tor-hosted platform to provide ransomware embedded in PDF files (targeting both Windows and macOS). The group offers a tiered subscription model—“TEST,” “BASIC,” and “ELITE”—allowing affiliates varying degrees of customization, offline capability, and support based on the package purchased. As of the latest reporting, no victims are publicly listed, though data leak publications likely require a subscription to access. The operation suggests an organized, business‑like structure, distinct from opportunistic one‑off strains.
Reports & references
- ransomlook.io — Contfr (report)
- cyjax.com — Contfraversy In Ransomland Tor Based Site Emerges For New French Speaking Raas Operation Contfr (report)