Conti was a Russian-speaking cybercriminal ransomware operation active from 2020 until its 2022 collapse, widely regarded as one of the most prolific double-extortion groups of its period and often described as a successor to Ryuk. The group combined targeted network intrusions, large-scale data theft, and rapid multithreaded file encryption, then pressured victims through leak-site publication threats and aggressive negotiation tactics. Conti publicly aligned itself with Russia during the early phase of the Russia-Ukraine war, after which internal chat logs and training materials were leaked, exposing the group’s organization, tooling, and affiliate tradecraft. Conti’s operations relied on an ecosystem of affiliates, access brokers, and malware partnerships. Reported access vectors and enabling malware included TrickBot, BazarLoader, QakBot, IcedID, Emotet, phishing, exposed RDP, VPN weaknesses, and exploitation of vulnerable internet-facing systems. Once inside victim environments, Conti operators and affiliates commonly used Cobalt Strike for post-exploitation, conducted credential theft and Active Directory compromise, escalated privileges, moved laterally with administrative tools and remote execution methods, exfiltrated data with tools such as Rclone and later Exmatter in some observed cases, and disabled defenses and recovery mechanisms including shadow copies and security tooling. The Conti ransomware payload itself used layered in-memory execution with shellcode and reflective loading, encrypted APIs and strings, anti-analysis logic, mutex-based execution control, and operator command-line options. It encrypted files with ChaCha8 and protected per-file key material with an embedded RSA public key. The malware could target local systems, accessible network shares, and remote hosts over SMB, while also using Windows Restart Manager to close locking applications and WMI to delete shadow copies. Conti was not a worm, but it supported operator-driven network-wide encryption at scale. Victimology spanned a broad set of sectors and countries, including healthcare, education, financial organizations, IT services, legal, charitable, food manufacturing, pharmaceuticals, logistics, oil-related entities, and other enterprises and public-facing organizations. The group was associated with more than 30 observed victim postings per month on average in 2021 and at one point accounted for roughly a quarter of surveyed leak-site victims among major ransomware groups. Conti maintained internal manuals for affiliates covering reconnaissance, scanning, SMB brute forcing, Kerberoasting, privilege escalation, domain takeover, NTDS dumping, persistence, defense evasion, and data exfiltration. Leaked materials and subsequent reporting also tied the broader Conti ecosystem to extortion-only activity through Karakurt, which was described as Conti’s extortion arm before Conti ceased operations. After the group’s disintegration in 2022, researchers and industry reporting linked former members or successor elements to later operations including Royal and Black Basta.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
Microsoft announced the existence of CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, and with their powers combined, they are ProxyShell. These vulnerabilities... leverage pre-auth path confusion for ACL bypass, elevation of privilege on the Exchange PowerShell backend, and post-auth arbitrary file writes to install a web shell onto the compromised system. | Pre-Auth Path Confusion ACL Bypass (CVE-2021-34473)
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
They check for the “PrintNightmare” vulnerability (CVE-2021-34527) in Windows Print spooler service, EternalBlue vulnerability (CVE-2017-0144) in Microsoft Windows Server Message Block, and the “Zerologon” vulnerability (CVE-2020-1472) in Microsoft Active Directory Domain Controller.
They check for the “PrintNightmare” vulnerability (CVE-2021-34527) in Windows Print spooler service, EternalBlue vulnerability (CVE-2017-0144) in Microsoft Windows Server Message Block, and the “Zerologon” vulnerability (CVE-2020-1472) in Microsoft Active Directory Domain Controller.
2 more CVEs tied to this actor tracked in Mallory.
186 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation that closely partnered with and later effectively absorbed TrickBot talent and access capabilities, using that access to breach victim networks, gain administrative control, steal data, and deploy ransomware with double-extortion tactics.
Named as one of multiple ransomware groups operating data leak sites and listing fresh victims.
Referenced as a major ransomware operation whose leaked source code reshaped the ransomware ecosystem.
Referenced as the threat actor group Bentley was allegedly involved with; not the primary subject of this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.