Conti, also known as the Conti Gang, Conti Group, and Conti Ransomware Group, was a financially motivated, Russia-associated cybercriminal syndicate operating a ransomware-as-a-service program. First identified in 2020, it supplied affiliates with ransomware, operational guidance, and support in exchange for a share of ransom proceeds. Its attacks included U.S. healthcare and emergency-service networks, Ireland’s Health Service Executive in May 2021, and Costa Rican government organizations in 2022. The operation shut down in 2022 following internal disclosures and a political rift between members supporting Russia and Ukraine. Conti combined network-wide encryption with theft of sensitive information to support double extortion. Affiliates prioritized financial records, client information, security policies, and cyberinsurance documents to assess victims’ ability to pay and strengthen negotiation leverage. Karakurt functioned as a related data-extortion operation within the syndicate: when Conti encryption was blocked, attackers used the Karakurt name to demand payment over already-stolen information. Conti actors also began selling access to compromised victim networks in October 2021. Initial access involved malware-delivery relationships with Emotet, IcedID, and TrickBot, initial access brokers such as EXOTIC LILY, and exploitation of vulnerable internet-facing systems. Post-compromise operations emphasized Active Directory reconnaissance, credential dumping, Kerberoasting, password guessing, privilege escalation, and lateral movement to obtain domain-wide administrative access. Tooling included Cobalt Strike, Mimikatz, AdFind, BloodHound, network scanners, and legitimate remote-access applications used to maintain access. Affiliate guidance covered exploitation of Zerologon and PrintNightmare, bulk exfiltration with Rclone, deletion of shadow copies, interference with security tools, and coordinated ransomware deployment. An affiliate training-playbook leak in August 2021 and disclosures of internal communications and source code in early 2022 exposed Conti’s organizational structure and attack procedures. Its dissolution dispersed personnel into the wider cybercrime ecosystem rather than ending the activity of all former members.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
37 CVEs this actor has used in observed campaigns. 37 of them exploited in the wild.
“Conti and its affiliates will try to leverage Zerologon to obtain domain admin privileges.”
Microsoft announced the existence of CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, and with their powers combined, they are ProxyShell. These vulnerabilities... leverage pre-auth path confusion for ACL bypass, elevation of privilege on the Exchange PowerShell backend, and post-auth arbitrary file writes to install a web shell onto the compromised system. | Pre-Auth Path Confusion ACL Bypass (CVE-2021-34473)
Listed in the elevation of privilege section as a Windows Print Spooler Remote Code Execution Vulnerability.
Apache Log4j <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
We have identified multiple cases of Exchange servers compromised with ProxyShell (chaining CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) in September and October.
32 more CVEs tied to this actor tracked in Mallory.
209 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware group connected to the botnet and loader ecosystem discussed in the article. Conti used IcedID and TrickBot for initial access and ransomware staging, and its operators overlapped heavily with the TrickBot group. The article states that Conti fractured in early 2022.
A defunct ransomware syndicate mentioned as the likely former affiliation of some Silent Ransom Group core members. No current Conti involvement in the described activity is established.
Defunct ransomware syndicate mentioned as the possible former organization of Silent Ransom Group's core members. The connection is assessed as likely, not confirmed.
Mentioned only as historical background: Conti shut down in 2022, before Silent Ransom Group emerged. The article does not establish an organizational relationship or describe Conti’s operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.