Conti is a ransomware family first identified in 2020 and distributed through a ransomware-as-a-service operation. It encrypts data across compromised organizational networks to extort payment. The operation combined encryption with data theft and threats of disclosure, including attacks against healthcare and emergency-service organizations. Notable victims included Ireland’s Health Service Executive in May 2021. Conti has been deployed by the ransomware affiliate Pistachio Tempest, also known as FIN12.
Conti supports rapid, parallel file encryption, discovers remote hosts, and can propagate to other machines through network shared drives. Its Windows implementation uses Windows Restart Manager to release files held open by applications before encryption. Conti has also loaded and executed encrypted DLLs in memory. Affiliate documentation included Linux and VMware ESXi encryption options, although those variants had not been observed in the wild at the time that documentation was analyzed.
Deployment chains have involved QakBot, TrickBot, Emotet, BazarLoader, and IcedID, alongside access supplied by initial access brokers such as EXOTIC LILY. Affiliates used credential dumping, Active Directory reconnaissance, remote-access software, and exploitation of vulnerabilities including Zerologon and PrintNightmare to obtain privileged access and deploy ransomware broadly. These intrusion activities were performed with supporting tools rather than necessarily by the encryptor itself. Stolen information was used for extortion under the Karakurt name when Conti encryption was blocked.
Conti’s affiliate playbook leaked in 2021, followed by internal communications and source-code disclosures in 2022. The exposed source code enabled reuse by other actors, including NB65 in attacks against Russian targets, and contributed to later ransomware implementations such as LockBit Green and Conti-derived DragonForce variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Listed in the elevation of privilege section as a Windows Print Spooler Remote Code Execution Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Update Notification Manager Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Error Reporting Manager Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Certificate Dialog Elevation of Privilege Vulnerability.
Listed among initial access vulnerabilities: VMware vSphere Client Remote Code Execution Vulnerability.
Listed among initial access vulnerabilities: VMware vCenter Server Remote Code Execution Vulnerability.
Listed among initial access vulnerabilities used by Conti and its affiliates: Fortinet FortiOS Improper Access Control Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows AppX Deployment Extensions Elevation of Privilege Vulnerability.
According to a recently leaked threat actor “playbook,” Conti actors also exploit vulnerabilities in unpatched assets to escalate privileges and move laterally across a victim’s network, including the "Zerologon" vulnerability (CVE-2020-1472) in Microsoft Active Directory Domain Controller systems.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Microsoft Windows Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Elevation of Privilege Vulnerability.
Listed among initial access vulnerabilities: Microsoft Exchange Validation Key Remote Code Execution Vulnerability.
Listed among initial access vulnerabilities: Windows SMBv3 Client/Server Remote Code Execution Vulnerability (“SMBGhost”).
The manual contains an MS17-010 section discussing vulnerable Windows systems. The report also states that WannaCry, Petya, and NotPetya leveraged EternalBlue.
“Conti and its affiliates have used CVE-2021-44228, also known as Log4Shell, as part of attacks beginning in late 2021.”
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Win32k Elevation of Privilege Vulnerability.
Listed as a Win32k Memory Corruption Elevation of Privilege Vulnerability. The article states that the oldest listed flaw was patched in 2015.
Listed among initial access vulnerabilities: Microsoft Exchange Server Remote Code Execution Vulnerability ("ProxyLogon").
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Microsoft Windows Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Win32k Elevation of Privilege Vulnerability.
Listed among initial access vulnerabilities: VMware vSphere Client Remote Code Execution Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Elevation of Privilege Vulnerability.
Listed among initial access vulnerabilities used by Conti and its affiliates: Fortinet FortiOS Path Traversal/Arbitrary File Read Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Task Scheduler Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows UPnP Service Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability.
Listed among initial access vulnerabilities: Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Win32k Elevation of Privilege Vulnerability.
Listed among elevation of privilege vulnerabilities used by Conti and its affiliates: Windows Win32k Elevation of Privilege Vulnerability.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | A Hive ransomware affiliate has been targeting Microsoft Exchange servers vulnerable to ProxyShell security issues... ProxyShell is a set of three vulnerabilities in the Microsoft Exchange Server that allow remote code execution without authentication on vulnerable deployments. The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
25 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It dropped QakBot and TrickBot, which in turn deployed Ryuk and Conti ransomware.
When Conti's ransomware encryptor was blocked in attacks, the hackers extorted the victim using the already stolen data under the Karakurt name rather than the Conti brand.
A disgruntled affiliate for Conti, a prolific ransomware group that emerged in 2020 and has made over $180 million in profits, leaked the group’s affiliate playbook.
In March 2022, when the Conti ransomware operation suffered a data breach, their source code was leaked online as well. This source code was quickly used by the NB65 hacking group to launch ransomware attacks on Russia.
This rise is largely attributed to their dual use of two powerful ransomware variants: a repurposed version of LockBit, and a heavily customized fork of Conti.
Security researcher Bushidotoken noted overlaps between Qilin’s leak-site victims and those of BlackCat and Conti.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Conti ransomware can retrieve the ARP cache from the local system by using the GetIpNetTable() API call.
Conti ransomware can enumerate routine network connections from a compromised host.
The malware employs intermittent encryption and evasion techniques to bypass EDR and anti-ransomware defenses.
290 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed through loader and banking-trojan access chains. The article associates it with Emotet, QakBot, TrickBot, and IcedID, emphasizing substantial operational overlap with TrickBot.
Ransomware used to evaluate file-lifecycle backup triggers and their effectiveness in preserving clean files against encryption. The abstract provides no family-specific behavior or results.
Predecessor ransomware associated with Akira through reported code and tradecraft overlap. The article describes the Conti operation as having disbanded in 2022, but does not establish definitive individual or geographic attribution for Akira.
Mentioned as background lineage for Royal, which the article describes as a Conti spinoff. No technical details about Conti malware are provided.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.