Skip to main content
Back to Ransomware Database
Ransomware Group

conti

Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.

Known victims351

Threat Level

HIGH

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Mimikatz
  • ProcDump
  • Router Scan
  • SharpChrome

DefenseEvasion

  • GMER
  • PCHunter

DiscoveryEnum

  • AdFind
  • Bloodhound
  • PowerView
  • Seatbelt
  • ShareFinder
  • +2 more

Exfiltration

  • Dropfiles
  • MEGA
  • Qaz[.]im
  • RClone
  • Sendspace
  • +1 more

LOLBAS

  • BITSAdmin
  • NTDS Utility (ntdsutil)
  • PsExec
  • WMIC

Offsec

  • Cobalt Strike
  • Metasploit
  • Meterpreter
  • PowerShell Empire
  • PowerSploit
  • +1 more

RMM-Tools

  • AnyDesk
  • Atera
  • Splashtop
0

Check If You're Affected

Search our database to see if your organization appears in conti's victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request