Monti is a ransomware threat actor and associated ransomware family that emerged after the decline of Conti and is widely assessed as either a Conti rebrand or a separate operation built from Conti source code leaked in 2022. It has been described as a Conti doppelganger because it closely mirrors Conti tradecraft and tooling, and code-level similarities have been noted between the two families. Reporting also links the operation at various times to Mikhail Matveev, also known as Wazawaka, a prominent Russian-speaking cybercriminal associated with multiple ransomware programs. Monti conducts financially motivated ransomware and extortion operations. The group has been observed targeting healthcare organizations and critical infrastructure, and has publicly claimed victims through a leak site. Healthcare appears to be a notable focus area, with reporting indicating a comparatively high share of Monti activity directed at that sector. Victimology also includes specialty medical providers. Monti’s operations include data theft and extortion in addition to encryption, consistent with double-extortion ransomware. The group has used coercive pressure tactics beyond standard leak threats, including public humiliation of victims and threats to report alleged criminal or regulatory issues discovered in stolen data to authorities. Reporting also notes use of information-stealing malware in ransomware operations associated with Monti, including malware aimed at extracting credentials from Veeam environments to support follow-on access. Operationally, Monti intrusions have included defense-evasion tooling used immediately prior to ransomware deployment. In at least one observed 2025 intrusion, operators deployed an EDR-killing utility derived from public BYOVD tradecraft and reimplemented it in C++, indicating active adaptation of tooling to disable endpoint protections before encryption. Monti has also been characterized as using stealthy encryption in attacks on critical infrastructure. Known aliases include Storm-1194. Monti is best understood as part of the post-Conti Russian-speaking ransomware ecosystem, combining leaked-code lineage, affiliate-style tooling choices, credential theft, endpoint defense suppression, data exfiltration, and aggressive extortion tactics.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group observed deploying a reimplemented TfSysMon-Killer EDR killer during an intrusion.
Referenced as a possible Conti rebrand or a new ransomware variant derived from leaked Conti source code.
Ransomware operations leveraging victim shaming/leak-site posting on the dark web; cited here as claiming/advertising a healthcare victim (Excelsior Orthopedics) following a 2024 hack.
Ransomware actor focusing on critical infrastructure; noted for stealthy encryption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.