Also known as: Conti
Executive Summary
Conti is an advanced ransomware-as-a-service weapon first seen in December 2019, commonly delivered via the TrickBot trojan to large corporations and governmental organizations across North America. After exfiltrating data, it encrypts files with AES‑256 and threatens public disclosure if ransoms are not paid. The malware utilizes HTTPS-based dynamic C2 for stealthy updates, modifies registry entries for persistence, and disables common security utilities. Its dual threat model—encryption plus extortion—makes Conti a high‑impact ransomware actor requiring robust monitoring and defense practices.
Enhanced Description
Conti is a sophisticated ransomware-as-a-service (RaaS) platform first detected in December 2019. The operation is tightly integrated with the TrickBot trojan, which delivers Conti to compromised Windows networks through credential theft, phishing drops or supply‑chain compromise. Once activated, Conti exfiltrates sensitive files and metadata before encrypting them with strong AES‑256 encryption, then appends .conti to the original filenames. The malware’s command‑and‑control (C2) infrastructure uses HTTPS connections to a dynamic DNS list, allowing attackers to update their servers without being easily blocked. In 2020 and 2021, Conti leveraged public cloud storage services such as Dropbox and Amazon S3 to host ransomware payloads and ransom notes. Attackers also exploited the popular RAT tool, Mimikatz, for credential dumping, enabling lateral movement across corporate environments. The group's focus has been major corporations and government agencies in North America, where they have threatened to publish exfiltrated data unless a payment is made. These tactics emphasize the double‑layered threat model of Conti: ransom for file recovery coupled with extortion through potential data leaks. Conti’s persistence mechanisms include modifying registry keys (e.g., HKCU\Software\Microsoft\Windows\CurrentVersion\Run) and creating malicious scheduled tasks. The malware can disable security tools such as Windows Defender by terminating related processes, further facilitating its spread and encryption operations. Overall, Conti demonstrates a classic RaaS model of rapid deployment, aggressive exfiltration, and financially motivated cryptography.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information is drawn from multiple public cybersecurity reports (Cybereason, Carbon Black, CybleInc) and reflects established intelligence regarding Conti’s behavior and delivery methods. However, specific details such as the exact encryption algorithm version, first/last seen dates, and full persistence mechanisms were not available in the source data. Further analysis of malware samples and network traffic would increase confidence for forensic investigators.
Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.(Citation: Cybereason Conti Jan 2021)(Citation: CarbonBlack Conti July 2020)(Citation: Cybleinc Conti January 2020)