Quantum is an enterprise-targeting ransomware family used in financially motivated ransomware-as-a-service operations. It encrypts victim systems and is associated with double-extortion attacks in which operators steal sensitive data before encryption and threaten its disclosure to pressure victims into paying. Its operations have targeted mid-market and larger enterprises, including Windows domain environments.
Quantum deployment has followed intrusions initiated through malicious email attachments that deliver Emotet. IcedID has also been used to deliver the ransomware. Observed attack chains include network enumeration and lateral movement with Cobalt Strike, remote access through Tactical RMM and AnyDesk, data exfiltration using Rclone, and domain-wide ransomware deployment. Operators have used PsExec and Windows Management Instrumentation for remote execution in Quantum incidents. These activities involve supporting malware and administrative tools rather than necessarily being native functions of the ransomware payload.
Quantum is associated with the former Conti criminal ecosystem and has been deployed by affiliates using multiple ransomware families. ShadowSyndicate was linked to Quantum activity in September 2022, and Vanilla Tempest has also used the family. Quantum payloads have been protected by crypters associated with ITG23. The ransomware is distinct from the similarly named malicious Windows shortcut-building tool and NSA surveillance capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Security researchers from Group-IB have been able to link this group to various ransomware incidents in the past, which include Quantum ransomware activity in September 2022.
Former Conti members rebranded under Quantum, which quickly rebranded to Royal and later rebranded again to BlackSuit in 2024.
...this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike, and the Ryuk, Conti, and Quantum ransomware strains.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond... In the academic literature, these are called 'man-in-the-middle' attacks... More specifically, they are examples of 'man-on-the-side' attacks.
By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond... In the academic literature, these are called 'man-in-the-middle' attacks... More specifically, they are examples of 'man-on-the-side' attacks.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS operation sharing staging infrastructure with Play.
Ransomware operation identified as a successor subgroup of former Conti members; it rebranded as Royal and subsequently BlackSuit.
A ransomware family listed among strains associated through transactions with Stern.
A ransomware family/group described as a Conti successor that rebranded first to Royal and later to BlackSuit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.