conti
Group profile
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.
MITRE ATT&CK TTPs
Initial Access
T1078.002Valid Accounts: Domain Accounts
Use of credentials purchased via Initial Access Brokers or harvested through prior compromises.
T1190Exploit Public-Facing Application
Exploitation of Log4Shell (CVE-2021-44228), ProxyShell, and Fortinet vulnerabilities to gain initial access to victim networks.
T1566.001Phishing: Spearphishing Attachment
Conti extensively uses BazarLoader and TrickBot delivered via spear-phishing emails with malicious Office document attachments containing macros.
Execution
Persistence
Privilege Escalation
T1068Exploitation for Privilege Escalation
Exploitation of PrintNightmare (CVE-2021-34527) and ZeroLogon (CVE-2020-1472) to escalate to SYSTEM or Domain Admin.
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
Rclone used to exfiltrate stolen data to MEGA and other cloud storage providers as part of the double extortion model.
Command and Control
Impact
T1486Data Encrypted for Impact
Conti ransomware uses ChaCha20 for file encryption with RSA-4096 for key protection. Multi-threaded encryption leverages up to 32 simultaneous threads for rapid encryption. Operates as RaaS.
T1490Inhibit System Recovery
Volume Shadow Copies deleted via vssadmin and wmic; Windows Backup Catalog deleted; recovery mode disabled via bcdedit.
Recent victims
showing 50 of 351| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2022-06-07 | A Alliance Steel | Manufacturing | |
| 2022-05-25 | L LCRD | Not Found | |
| 2022-05-25 | T The Contact Company | Business Services | |
| 2022-05-24 | C Central Restaurant Products | Agriculture and Food Production | |
| 2022-05-24 | S Schaumburg Park District | Public Sector | |
| 2022-05-24 | R RateGain | Technology | |
| 2022-05-23 | I Imenco AS | Energy | |
| 2022-05-23 | C Concepts in Millwork | Construction | |
| 2022-05-23 | E Eurofred | Manufacturing | |
| 2022-05-23 | A Agile Sourcing Partners | Business Services | |
| 2022-05-23 | A Alimentos y Frutos S.A. | Agriculture and Food Production | |
| 2022-05-23 | W Worksoft | Technology | |
| 2022-05-23 | O Omicron Consulting S.r.L | Business Services | |
| 2022-05-23 | P Pianca | Manufacturing | |
| 2022-05-23 | A Allcat Claims Service | Business Services | |
| 2022-05-17 | F FOR BlackCat and LockBit advert | Not Found | |
| 2022-05-14 | F For Costa Rica and US terrorists (Biden and his administration) | Not Found | |
| 2022-05-12 | C Cjk Group, Inc. | Business Services | |
| 2022-05-04 | E EYP | Not Found | |
| 2022-04-28 | L LARON an otp industrial solutions company | Manufacturing | |
| 2022-04-27 | A Attica Holdings S.A. | Transportation/Logistics | |
| 2022-04-27 | F For Peru | Not Found | |
| 2022-04-25 | E Elgin_Ca | Not Found | |
| 2022-04-23 | J Jasec | Not Found | |
| 2022-04-20 | A Attica Group | Hospitality and Tourism | |
| 2022-04-19 | I Instituto Meteorológico Nacional and racsa.go.cr | Public Sector | |
| 2022-04-19 | I Instituto Meteorológico Nacional | Public Sector | |
| 2022-04-19 | D Del Sol | Consumer Services | |
| 2022-04-19 | F For Costa Rica | Not Found | |
| 2022-04-18 | C Centris | Not Found | |
| 2022-04-18 | N Nordex SE | Energy | |
| 2022-04-17 | M Ministerio de Hacienda - República de Costa Rica | Public Sector | |
| 2022-04-17 | T Tucker Door & Trim | Construction | |
| 2022-04-15 | [ [IMPORTANT ANNOUNCEMENT!] | Not Found | |
| 2022-04-15 | C CJ Pony Parts | Consumer Services | |
| 2022-04-14 | B Big Horn Plastering of Colorado, Inc. | Construction | |
| 2022-04-14 | E Elevate Services | Business Services | |
| 2022-04-12 | T TIC International Corporation | Manufacturing | |
| 2022-04-11 | N Newlat Food SPA | Agriculture and Food Production | |
| 2022-04-11 | C CAE Services | Business Services | |
| 2022-04-11 | M MARTINELLI GINETTO | Agriculture and Food Production | |
| 2022-04-11 | E Eminox | Manufacturing | |
| 2022-04-10 | S Snap-on Incorporated | Manufacturing | |
| 2022-04-08 | W Wocklum Group | Manufacturing | |
| 2022-04-06 | B Barwick Bathroom Distribution LLP | Consumer Services | |
| 2022-04-05 | P panasonic | Technology | |
| 2022-04-04 | W Woningcorporatie ZAYAZ | Public Sector | |
| 2022-04-04 | T TRUSTFORD | Consumer Services | |
| 2022-04-03 | S SLH | Hospitality and Tourism | |
| 2022-04-03 | F Frey and Winkler GmbH | Manufacturing |

