Conti — Ransomware Profile
Conti was one of the most prolific and destructive ransomware operations before fragmenting in 2022 following its internal chat leak due to the Ukraine war.Also tracked as
WIZARD SPIDER, Wizard Spider, DEV-0193, DEV-0237, FIN12, GOLD BLACKBURN, Periwinkle Tempest, Pistachio Tempest, Storm-0193, Storm-0230, TEMP.MixMaster, Trickbot LLC, UNC2053, UNC1878, Grim Spider, ITG23, GOLD ULRICK
IntelFusions coverage (8)
- FBI and CISA warn of Gunra ransomware hitting hospitals 2026-08-10 · Ransomware
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16 · Ransomware
- BlackByte Ransomware Evolves: Four Vulnerable Drivers, ESXi Zero-Day Exploitation, and Victim Credentials Baked Into the Payload 2026-02-16 · Ransomware
- Operation Cronos Fallout: LockBit Admin Panel Exposed, 193 Affiliates Identified, and Post-Disruption Activity Reveals Inflated Victim Counts 2026-02-16 · Ransomware
- From Conti Code to ESXi Servers: SentinelOne Decodes Akira's Cross-Platform Ransomware Evolution 2026-02-16 · Ransomware
- LockBit Green: New Variant Incorporates Leaked Conti Source Code, Revealing Transitivity Links to BazaLoader and TrickBot Families 2026-02-16 · Ransomware
- CISA, FBI, and NSA Joint Advisory: Conti Ransomware Surpasses 1,000 Attacks with TrickBot, Cobalt Strike, and Double Extortion 2026-02-16 · Ransomware
- Wizard Spider's Sidoh (Ryuk Stealer): Keyword-Based FTP Exfiltration Tool Targeting Government, Military, and Financial Files with Ryuk Source Code DNA 2026-02-16 · Ransomware
Tools & malware
- AdFind Reconnaissance
- Anchor Backdoor
- BazarLoader Loader
- BloodHound Reconnaissance
- Cobalt Strike Offensive Security Tool
- Diavol Ransomware
- Emotet Loader
- Empire Post-Exploitation Framework
- LaZagne Credential Theft
- Mimikatz Credential Theft
- PsExec Lateral Movement
- Rubeus Credential Theft
- Ryuk Ransomware
- SystemBC Proxy
- TrickBot Loader
Vendor research
- FireEye Ryuk and Trickbot January 2019 FireEye Ryuk and Trickbot January 2019
- Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock
- Gold Blackburn Threat Profile Secureworks Counter Threat Unit
- CrowdStrike CrowdStrike
- How Microsoft names threat actors Microsoft
- Financially Motivated Threat Actor Pistachio Tempest Microsoft
- WIZARD SPIDER Update: Resilient, Reactive and Resolute Podlosky, A., Hanel, A. et al
- Ransomware Activity Targeting the Healthcare and Public Health Sector DHS/CISA
- Trickbot Rising - Gang Doubles Down on Infection Efforts to Amass Network Footholds Villadsen, O., et al
- Gold Blackburn Threat Profile Secureworks Counter Threat Unit
- Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock
- FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets Shilko, J., et al
- FireEye Ryuk and Trickbot January 2019 FireEye Ryuk and Trickbot January 2019
- Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware Hanel, A
- Unraveling the Spiderweb: Timelining ATT&CK Artifacts Used by GRIM SPIDER John, E. and Carvey, H
Countries linked to this actor
- Ireland targets
- Costa Rica targets