Monti is a ransomware family that emerged in 2022 and is widely assessed to be closely related to Conti, either as a rebrand by former Conti operators or as a new variant built from the Conti source code leaked that year. It has been described as a Conti doppelganger because it closely mirrors Conti tradecraft and tooling, and code analysis has identified strong similarity between Monti and Conti, including a very similar entry point.
Monti is associated with the broader post-Conti fragmentation of the ransomware ecosystem, in which affiliates and developers moved between brands after Conti’s operational decline. Reporting has linked Monti to activity by actors with prior Conti affiliations, and it has appeared alongside other major ransomware strains in enterprise-targeting intrusion sets.
Monti has been observed targeting Linux environments, including VMware ESXi systems, reflecting the broader shift of ransomware operators toward hypervisors and server infrastructure where a single compromise can disrupt many hosted workloads. In Linux-focused deployments, ransomware of this class typically emphasizes file encryption over complex modular functionality, often relying on external scripts, command-line parameters, webshells, or legitimate administration tools during the intrusion. Monti has been noted to generate a characteristic encryption log during execution.
High-confidence reporting supports classifying Monti as ransomware. Its operational context is consistent with enterprise extortion campaigns against organizational infrastructure rather than consumer-focused malware activity. Available information does not establish a single exclusive delivery mechanism for Monti itself, but it appears in an ecosystem where Linux and ESXi ransomware intrusions commonly begin through exploitation of exposed services, deployment of webshells, use of stolen SSH credentials, or brute-force access against internet-facing systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
one of the most common infection chains for Linux is exploiting a vulnerability in some exposed service of the victim’s servers. This is also true for vulnerabilities in ESXi, but there are also other cases, such as IceFire which exploits a vulnerability in an IBM technology (CVE-2022-47986)
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware variant whose code and entry point appear highly similar to Conti, possibly representing either a Conti rebrand or a new strain built from leaked Conti source code.
Ransomware operation referenced as minimal activity in Q2 2025 (no additional detail provided).
Linux ransomware family included in the study. The content notes it may depend on parameters/configuration for target paths, can generate a result.txt log during encryption, and includes ESXi-related commands to stop VMs before encryption.
Ransomware strain used by at least one former Conti affiliate as part of post-Conti affiliate migration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.