Internal documentation leaked by a self-described Conti penetration tester exposed how the ransomware group guided affiliates through reconnaissance, credential theft, privilege escalation, persistence, lateral movement, data exfiltration, and encryption. FortiGuard Labs and ReliaQuest described instructions to exploit Zerologon and PrintNightmare, pursue privileged administrator accounts, maintain access through remote-access tools, and blend into legitimate administrative activity to avoid detection. Operators assessed victims’ revenue and searched for financial records, cybersecurity insurance policies, backups, and hypervisors to strengthen ransom demands and maximize disruption.
The manuals described using rclone and MEGA to exfiltrate data before encryption, supporting Conti’s theft-and-encryption extortion model. They also referenced Linux and VMware ESXi encryption capabilities, although FortiGuard had not observed those variants in the wild when its August 2021 report appeared. ReliaQuest’s June 2022 analysis noted that Conti had shut down operations in May 2022 and recommended least privilege, credential auditing, process-hierarchy monitoring, enhanced PowerShell auditing, and detection of suspicious Volume Shadow Copy access to counter the documented techniques.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Conti shut down its operations in May 2022, according to ReliaQuest's analysis of the gang's leaked attack materials.
A self-described Conti penetration tester publicly leaked password-protected archives, operational instructions, and reference files intended for affiliates. The materials exposed the gang's workflow for reconnaissance, credential theft, persistence, data exfiltration, and ransomware deployment.
FortiGuard Labs analyzed the leaked “CobaltStrike Manuals_V2 Active Directory” manual, detailing exploitation of Zerologon and PrintNightmare, remote-access persistence, and exfiltration through MEGA and Rclone. The manual also documented Linux and VMware ESXi encryption capabilities that the researchers had not observed in the wild.
A Conti ransomware attack disrupted Irish Health Service operations and reportedly involved the exfiltration of more than 700 GB of personally identifiable information and database data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.