Back to Ransomware Database
Ransomware Group
conti
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.
Known victims351
Threat Level
HIGH
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- Mimikatz
- ProcDump
- Router Scan
- SharpChrome
DefenseEvasion
- GMER
- PCHunter
DiscoveryEnum
- AdFind
- Bloodhound
- PowerView
- Seatbelt
- ShareFinder
- +2 more
Exfiltration
- Dropfiles
- MEGA
- Qaz[.]im
- RClone
- Sendspace
- +1 more
LOLBAS
- BITSAdmin
- NTDS Utility (ntdsutil)
- PsExec
- WMIC
Offsec
- Cobalt Strike
- Metasploit
- Meterpreter
- PowerShell Empire
- PowerSploit
- +1 more
RMM-Tools
- AnyDesk
- Atera
- Splashtop
Check If You're Affected
Search our database to see if your organization appears in conti's victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request