Conti (ELF)

Aliases: Conti Locker

First seen
2020-12-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:02:47

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

Conti is a sophisticated ransomware family that encrypts a victim's data and demands ransom for decryption. It is known for its double extortion tactics, threatening to release stolen data if the ransom is not paid.

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
  • Microsoft — Re54L7V (report)
  • media.kasperskycontenthub.com — Common Ttps Of The Modern Ransomware Low Res (report)
  • Kaspersky — 106457 (report)
  • intel471.com — Malware Before Ransomware Trojan Information Stealer Cobalt Strike (report)
  • advintel.io — Advintel S State Of Emotet Aka Spmtools Displays Over Million Compromised Machines Through 2022 (report)
  • esentire.com — Analysis Of Leaked Conti Intrusion Procedures By Esentires Threat Response Unit Tru (report)
  • secureworks.com — Gold Ulrick Continues Conti Operations Despite Public Disclosures (report)
  • threatstop.com — First Conti Then Hive Costa Rica Gets Hit With Ransomware Again (report)
  • trellix.com — Conti Group Targets Esxi Hypervisors With Its Linux Variant (report)
  • youtube.com — Watch (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Conti (report)
  • resources.prodaft.com — Wazawaka Report (report)
  • damonmccoy.com — Ransomware Ecrime22 (report)
  • justice.gov — Multiple Foreign Nationals Charged Connection Trickbot Malware And Conti Ransomware (report)
  • shadowbanker.io — Shadow Banker Makes Glorious Return Interviews Guy Exposing Conti Command Control (report)

External references