Quantum is a ransomware strain and associated criminal brand that emerged in the post-Conti ecosystem and is widely linked to former Conti operators and affiliates. Reporting consistently places Quantum among the successor groups that appeared after Conti’s 2022 collapse, with subsequent rebranding into Royal and later BlackSuit. It has been associated with enterprise-focused double-extortion operations in which attackers steal data before encrypting systems and then use the threat of publication to pressure victims.
Observed Quantum intrusions commonly involve a broader multi-stage attack chain rather than direct standalone deployment. Initial access and staging have been linked to malware and access ecosystems such as Emotet, Qakbot, Bumblebee, TrickBot-related tooling, IcedID, BazarLoader, and Cobalt Strike. Delivery has been tied to phishing-driven infections and, more broadly, to the loader and affiliate infrastructure used by financially motivated ransomware actors. In at least some cases, operators conducted extended hands-on-keyboard activity before ransomware execution, including enumeration, credential access, lateral movement, remote administration tool deployment, and data theft.
Post-compromise tradecraft associated with Quantum includes use of Cobalt Strike for command and control and lateral movement, remote execution via PsExec and WMI, and exfiltration with tools such as Rclone prior to domain-wide encryption. Quantum has also been discussed in the context of re-extortion behavior, reflecting pressure tactics beyond initial ransom demands. The malware primarily targets Windows enterprise environments and has appeared in campaigns affecting mid-market and larger organizations, including critical-sector victims through its later lineage under Royal and BlackSuit.
The name Quantum is also used in unrelated contexts, including a malicious LNK-builder tool and historical surveillance malware references, but those are distinct from the ransomware family and criminal operation described here.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike, and the Ryuk, Conti, and Quantum ransomware strains.
Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond... In the academic literature, these are called 'man-in-the-middle' attacks... More specifically, they are examples of 'man-on-the-side' attacks.
By exploiting that speed difference, these servers can impersonate a visited website to the target before the legitimate website can respond... In the academic literature, these are called 'man-in-the-middle' attacks... More specifically, they are examples of 'man-on-the-side' attacks.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family listed among strains associated through transactions with Stern.
A ransomware family/group described as a Conti successor that rebranded first to Royal and later to BlackSuit.
Referenced as a known malware family based on labels found on related malicious files in VirusTotal.
A ransomware subgroup/brand that emerged from Conti and then quickly rebranded to Royal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.