Conti — Ransomware Profile
Conti was one of the most prolific and destructive ransomware operations before fragmenting in 2022 following its internal chat leak due to the Ukraine war.Also tracked as
WIZARD SPIDER, Wizard Spider, DEV-0193, DEV-0237, FIN12, GOLD BLACKBURN, Periwinkle Tempest, Pistachio Tempest, Storm-0193, Storm-0230, TEMP.MixMaster, Trickbot LLC, UNC2053, UNC1878, Grim Spider, ITG23
Vendor research
- CrowdStrike CrowdStrike
- FireEye Ryuk and Trickbot January 2019 FireEye Ryuk and Trickbot January 2019
- Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware Hanel, A
- Unraveling the Spiderweb: Timelining ATT&CK Artifacts Used by GRIM SPIDER John, E. and Carvey, H
- Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock
- How Microsoft names threat actors Microsoft
- Ransomware Activity Targeting the Healthcare and Public Health Sector DHS/CISA
- WIZARD SPIDER Update: Resilient, Reactive and Resolute Podlosky, A., Hanel, A. et al
- Gold Blackburn Threat Profile Secureworks Counter Threat Unit
- FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets Shilko, J., et al
- Trickbot Rising - Gang Doubles Down on Infection Efforts to Amass Network Footholds Villadsen, O., et al
- Financially Motivated Threat Actor Pistachio Tempest Microsoft