Conti (ELF)
Aliases: Conti Locker
- First seen
- 2020-12-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:02:47
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
Conti is a sophisticated ransomware family that encrypts a victim's data and demands ransom for decryption. It is known for its double extortion tactics, threatening to release stolen data if the ransom is not paid.
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
- Microsoft — Re54L7V (report)
- media.kasperskycontenthub.com — Common Ttps Of The Modern Ransomware Low Res (report)
- Kaspersky — 106457 (report)
- intel471.com — Malware Before Ransomware Trojan Information Stealer Cobalt Strike (report)
- advintel.io — Advintel S State Of Emotet Aka Spmtools Displays Over Million Compromised Machines Through 2022 (report)
- esentire.com — Analysis Of Leaked Conti Intrusion Procedures By Esentires Threat Response Unit Tru (report)
- secureworks.com — Gold Ulrick Continues Conti Operations Despite Public Disclosures (report)
- threatstop.com — First Conti Then Hive Costa Rica Gets Hit With Ransomware Again (report)
- trellix.com — Conti Group Targets Esxi Hypervisors With Its Linux Variant (report)
- youtube.com — Watch (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Conti (report)
- resources.prodaft.com — Wazawaka Report (report)
- damonmccoy.com — Ransomware Ecrime22 (report)
- justice.gov — Multiple Foreign Nationals Charged Connection Trickbot Malware And Conti Ransomware (report)
- shadowbanker.io — Shadow Banker Makes Glorious Return Interviews Guy Exposing Conti Command Control (report)