HackerFeeds
All ransomware groups

conti

351 tracked victims
·first seen 2020-07-31·last activity 2022-06-07

Group profile

Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078.002Valid Accounts: Domain Accounts

    Use of credentials purchased via Initial Access Brokers or harvested through prior compromises.

  • T1190Exploit Public-Facing Application

    Exploitation of Log4Shell (CVE-2021-44228), ProxyShell, and Fortinet vulnerabilities to gain initial access to victim networks.

  • T1566.001Phishing: Spearphishing Attachment

    Conti extensively uses BazarLoader and TrickBot delivered via spear-phishing emails with malicious Office document attachments containing macros.

TA0002

Execution

  • T1047Windows Management Instrumentation

    WMI leveraged for remote command execution across victim infrastructure.

  • T1059.001Command and Scripting Interpreter: PowerShell

    PowerShell used extensively for payload deployment, Cobalt Strike beacon staging, and post-exploitation activity.

TA0003

Persistence

  • T1136.002Create Account: Domain Account

    New domain accounts created for persistent access and to facilitate lateral movement with elevated privileges.

  • T1547.001Boot or Logon Autostart Execution: Registry Run Keys

    Registry Run keys used to maintain persistence of backdoor tools across reboots.

TA0004

Privilege Escalation

  • T1068Exploitation for Privilege Escalation

    Exploitation of PrintNightmare (CVE-2021-34527) and ZeroLogon (CVE-2020-1472) to escalate to SYSTEM or Domain Admin.

TA0005

Defense Evasion

  • T1218.011Signed Binary Proxy Execution: Rundll32

    Rundll32 used to execute malicious DLLs and evade application control.

  • T1562.001Disable or Modify Tools

    Windows Defender, AV products, and EDR tools disabled via PowerShell, registry modification, or Group Policy Objects.

TA0006

Credential Access

  • T1003.001OS Credential Dumping: LSASS Memory

    Mimikatz used to dump LSASS memory for credential harvesting across compromised hosts.

  • T1003.003OS Credential Dumping: NTDS

    Active Directory NTDS.dit extracted to obtain all domain account password hashes.

TA0007

Discovery

  • T1046Network Service Discovery

    Network scanning using Nmap, SoftPerfect Network Scanner, and custom scripts to enumerate the internal network.

  • T1482Domain Trust Discovery

    BloodHound used to enumerate Active Directory and identify attack paths to high-value targets.

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    RDP used for lateral movement using harvested credentials across the victim network.

  • T1021.002Remote Services: SMB/Windows Admin Shares

    PsExec used to deploy Cobalt Strike beacons and the ransomware payload across the network.

TA0009

Collection

  • T1005Data from Local System

    Sensitive documents, financial records, and PII collected from compromised hosts prior to encryption.

  • T1560.001Archive Collected Data: Archive via Utility

    7-Zip used to compress and archive stolen data for exfiltration.

TA0010

Exfiltration

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Rclone used to exfiltrate stolen data to MEGA and other cloud storage providers as part of the double extortion model.

TA0011

Command and Control

  • T1071.001Application Layer Protocol: Web Protocols

    Cobalt Strike beacons communicate via HTTPS to actor-controlled team servers for C2 operations.

  • T1219Remote Access Software

    AnyDesk and Atera agent installed as persistent backdoors for remote access.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Conti ransomware uses ChaCha20 for file encryption with RSA-4096 for key protection. Multi-threaded encryption leverages up to 32 simultaneous threads for rapid encryption. Operates as RaaS.

  • T1490Inhibit System Recovery

    Volume Shadow Copies deleted via vssadmin and wmic; Windows Backup Catalog deleted; recovery mode disabled via bcdedit.

Recent victims

showing 50 of 351
DateWebsite / victimSectorCountry
2022-06-07
A
Alliance Steel
Manufacturing
2022-05-25
L
LCRD
Not Found
2022-05-25
T
The Contact Company
Business Services
2022-05-24
C
Central Restaurant Products
Agriculture and Food Production
2022-05-24
S
Schaumburg Park District
Public Sector
2022-05-24
R
RateGain
Technology
2022-05-23
I
Imenco AS
Energy
2022-05-23
C
Concepts in Millwork
Construction
2022-05-23
E
Eurofred
Manufacturing
2022-05-23
A
Agile Sourcing Partners
Business Services
2022-05-23
A
Alimentos y Frutos S.A.
Agriculture and Food Production
2022-05-23
W
Worksoft
Technology
2022-05-23
O
Omicron Consulting S.r.L
Business Services
2022-05-23
P
Pianca
Manufacturing
2022-05-23
A
Allcat Claims Service
Business Services
2022-05-17
F
FOR BlackCat and LockBit advert
Not Found
2022-05-14
F
For Costa Rica and US terrorists (Biden and his administration)
Not Found
2022-05-12
C
Cjk Group, Inc.
Business Services
2022-05-04
E
EYP
Not Found
2022-04-28
L
LARON an otp industrial solutions company
Manufacturing
2022-04-27
A
Attica Holdings S.A.
Transportation/Logistics
2022-04-27
F
For Peru
Not Found
2022-04-25
E
Elgin_Ca
Not Found
2022-04-23
J
Jasec
Not Found
2022-04-20
A
Attica Group
Hospitality and Tourism
2022-04-19
I
Instituto Meteorológico Nacional and racsa.go.cr
Public Sector
2022-04-19
I
Instituto Meteorológico Nacional
Public Sector
2022-04-19
D
Del Sol
Consumer Services
2022-04-19
F
For Costa Rica
Not Found
2022-04-18
C
Centris
Not Found
2022-04-18
N
Nordex SE
Energy
2022-04-17
M
Ministerio de Hacienda - República de Costa Rica
Public Sector
2022-04-17
T
Tucker Door & Trim
Construction
2022-04-15
[
[IMPORTANT ANNOUNCEMENT!]
Not Found
2022-04-15
C
CJ Pony Parts
Consumer Services
2022-04-14
B
Big Horn Plastering of Colorado, Inc.
Construction
2022-04-14
E
Elevate Services
Business Services
2022-04-12
T
TIC International Corporation
Manufacturing
2022-04-11
N
Newlat Food SPA
Agriculture and Food Production
2022-04-11
C
CAE Services
Business Services
2022-04-11
M
MARTINELLI GINETTO
Agriculture and Food Production
2022-04-11
E
Eminox
Manufacturing
2022-04-10
S
Snap-on Incorporated
Manufacturing
2022-04-08
W
Wocklum Group
Manufacturing
2022-04-06
B
Barwick Bathroom Distribution LLP
Consumer Services
2022-04-05
P
panasonic
Technology
2022-04-04
W
Woningcorporatie ZAYAZ
Public Sector
2022-04-04
T
TRUSTFORD
Consumer Services
2022-04-03
S
SLH
Hospitality and Tourism
2022-04-03
F
Frey and Winkler GmbH
Manufacturing