Conti — Malware Profile
Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.
MITRE ATT&CK techniques (16)
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1021.002 SMB/Windows Admin Shares
- T1027 Obfuscated Files or Information
- T1049 System Network Connections Discovery
- T1055.001 Dynamic-link Library Injection
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1080 Taint Shared Content
- T1083 File and Directory Discovery
- T1106 Native API
- T1135 Network Share Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
IntelFusions coverage
- From Conti Code to ESXi Servers: SentinelOne Decodes Akira's Cross-Platform Ransomware Evolution 2026-02-16
- BlackByte Ransomware Evolves: Four Vulnerable Drivers, ESXi Zero-Day Exploitation, and Victim Credentials Baked Into the Payload 2026-02-16
- CISA, FBI, and NSA Joint Advisory: Conti Ransomware Surpasses 1,000 Attacks with TrickBot, Cobalt Strike, and Double Extortion 2026-02-16
- Operation Cronos Fallout: LockBit Admin Panel Exposed, 193 Affiliates Identified, and Post-Disruption Activity Reveals Inflated Victim Counts 2026-02-16
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16
- LockBit Green: New Variant Incorporates Leaked Conti Source Code, Revealing Transitivity Links to BazaLoader and TrickBot Families 2026-02-16
- FBI and CISA warn of Gunra ransomware hitting hospitals 2026-08-10