Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang. Known victims: 351 32 negotiation log(s) available, 4 ransom note(s) on file
Objectives
Executive Summary
Conti is a highly damaging ransomware group, attributed to the Wizard Spider cybercrime collective based in Russia. Known for rapid encryption and network spread, Conti has targeted numerous industries globally since its emergence in 2020, employing double extortion tactics. The U.S. government has offered a $10 million reward for information leading to their apprehension.
Goals & Targeting
Conti's primary motivation is financial gain, targeting organizations with deep financial reserves to maximize ransom yields. They strategically focus on sectors where data breaches cause maximum disruption—healthcare for patient data, education for student records, and manufacturing for supply chain information. Their geographic reach includes the U.S., UK, Spain, Italy, Germany, Australia, Japan, Canada, Brazil, Mexico, UAE, India, Russia, China, Taiwan, Hong Kong, and South Korea, reflecting a global approach to maximize victim pool.
Enhanced Description
Conti is a sophisticated ransomware family linked to the Wizard Spider group, first detected in July 2020. It is renowned for its rapid encryption and lateral movement capabilities, making it particularly dangerous for organizations dependent on critical data systems. The ransomware operates using a double extortion model—encrypting victim data and threatening to leak sensitive information unless a substantial ransom is paid in cryptocurrency. Conti has targeted a diverse range of sectors including healthcare, education, retail, and manufacturing, with known victims spanning 351 entities across multiple countries. The group's ability to disrupt business operations and demand significant ransoms has made it one of the most notable cybercriminal organizations globally.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Conti's campaigns typically involve targeting medium to large organizations across various sectors. They employ phishing emails with malicious links or attachments to gain initial access, followed by rapid deployment of ransomware and encryption of systems. Double extortion is a hallmark, as Conti not only encrypts data but also threatens to leak it unless ransoms are paid in cryptocurrency like Bitcoin or Monero. Notable campaigns have included significant attacks on healthcare providers, causing disruptions to patient care.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Conti's existence and its association with the Wizard Spider group, driven by media reports, law enforcement statements, and victimology data. However, precise TTPs, such as exact tools and techniques employed, remain partially unknown due to limited linked IOCs and campaign details.
No techniques linked yet.
No tools linked yet.
Conti Ransomware
Imported from MISP event #255 (0319b483-5973-4932-91ea-5a44c2975b24).
May 16, 2021
TLP:CLEARNo observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
386
IOCs
0
Observed Data
0
Tactics