Monti is a ransomware group first observed in June 2022 that initially copied nearly all of Conti's leaked source code, pivoting to target government, legal, and healthcare entities, later releasing a new Linux variant in 2023 with significantly less Conti code similarity, and experimenting with an affiliate model. Known victims: 110 2 ransom note(s) on file
Objectives
Executive Summary
Monti is a medium-sophistication criminal ransomware group first seen in December 2022, initially using Conti's leaked source code. Targeting government, legal, and healthcare sectors, Monti has expanded its operations by introducing a new Linux variant in 2023 and experimenting with an affiliate model to increase its attack reach. With 110 known victims and active until May 2025, Monti poses a significant financial threat through ransom demands.
Goals & Targeting
Monti's strategic objectives are centered around organizational-gain through financial exploitation using ransomware. Initially targeting government institutions but shifting to legal and healthcare sectors likely reflects an assessment of high-value targets with significant data or operational downtime stakes. Their affiliate model suggests a focus on expanding their attack capacity and geographic reach to maximize profits and impact.
Enhanced Description
Monti emerged in late 2022 as a ransomware group, initially leveraging nearly all of Conti's leaked source code to conduct attacks. Unlike many other groups, Monti shifted its primary targets from private-sector businesses to政府机构、法律和医疗 healthcare entities. This pivot was likely an attempt to exploit sectors with potentially higher financial incentives or less robust cybersecurity measures compared to corporate environments. In 2023, Monti released a new Linux variant of their ransomware, signaling an evolution in their operations and reducing reliance on Conti's code, which may have aimed to avoid detection or association with the original group. The introduction of an affiliate program further indicates Monti's strategy to broaden its attack footprint by recruiting others to conduct attacks on their behalf, a common tactic among successful cybercriminal groups to scale operations. With 110 known victims and two published ransom notes, Monti has demonstrated both operational persistence and a clear focus on extorting financial gains from targeted organizations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Monti's campaigns have targeted critical infrastructure sectors, leveraging their evolving ransomware capabilities. Notable patterns include their affiliate recruitment strategy and the introduction of a Linux variant to diversify attack vectors. With over 110 victims, Monti has demonstrated consistent activity since 2022, adapting their methods to maintain operational effectiveness.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Monti's details is high due to the availability of their description, victim count, and operational timeline. Limited specific information on attack techniques and tools used adds some uncertainty but the group’s evolution over time is well-documented.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics