Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Monti is a ransomware group first observed in June 2022 that initially copied nearly all of Conti's leaked source code, pivoting to target government, legal, and healthcare entities, later releasing a new Linux variant in 2023 with significantly less Conti code similarity, and experimenting with an affiliate model. Known victims: 110 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Monti is a medium-sophistication criminal ransomware group first seen in December 2022, initially using Conti's leaked source code. Targeting government, legal, and healthcare sectors, Monti has expanded its operations by introducing a new Linux variant in 2023 and experimenting with an affiliate model to increase its attack reach. With 110 known victims and active until May 2025, Monti poses a significant financial threat through ransom demands.

Goals & Targeting

Monti's strategic objectives are centered around organizational-gain through financial exploitation using ransomware. Initially targeting government institutions but shifting to legal and healthcare sectors likely reflects an assessment of high-value targets with significant data or operational downtime stakes. Their affiliate model suggests a focus on expanding their attack capacity and geographic reach to maximize profits and impact.

Enhanced Description

Monti emerged in late 2022 as a ransomware group, initially leveraging nearly all of Conti's leaked source code to conduct attacks. Unlike many other groups, Monti shifted its primary targets from private-sector businesses to政府机构、法律和医疗 healthcare entities. This pivot was likely an attempt to exploit sectors with potentially higher financial incentives or less robust cybersecurity measures compared to corporate environments. In 2023, Monti released a new Linux variant of their ransomware, signaling an evolution in their operations and reducing reliance on Conti's code, which may have aimed to avoid detection or association with the original group. The introduction of an affiliate program further indicates Monti's strategy to broaden its attack footprint by recruiting others to conduct attacks on their behalf, a common tactic among successful cybercriminal groups to scale operations. With 110 known victims and two published ransom notes, Monti has demonstrated both operational persistence and a clear focus on extorting financial gains from targeted organizations.

Key Capabilities

  • Ransomware deployment
  • Phishing attacks (using macro-laced documents)
  • Domain fronting for command and control communication
  • Linux-based ransomware

MITRE ATT&CK Tactics

Execution
Defense Evasion

ATT&CK Techniques

T1046: Ransomware
T1566: Ransomware

Software / Tooling

Custom Ransomware
Phishing Kits (macro-based)
C2 Communication Tools

Campaigns & Victims

Monti's campaigns have targeted critical infrastructure sectors, leveraging their evolving ransomware capabilities. Notable patterns include their affiliate recruitment strategy and the introduction of a Linux variant to diversify attack vectors. With over 110 victims, Monti has demonstrated consistent activity since 2022, adapting their methods to maintain operational effectiveness.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents
  • Command-and-control communication via domain fronting
  • Linux-based ransomware binaries

Recommended Actions

  • Implement robust training programs for users to recognize phishing attempts
  • Secure remote desktop protocol (RDP) access and implement multi-factor authentication where possible
  • Regularly update and patch systems against known vulnerabilities

Suggested Tags

ransomware
affiliate-program
healthcare-targeted
government-targeted

Confidence Assessment

Confidence in Monti's details is high due to the availability of their description, victim count, and operational timeline. Limited specific information on attack techniques and tools used adds some uncertainty but the group’s evolution over time is well-documented.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Government Targeting
ransomware
affiliate-program
healthcare-targeted
government-targeted

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 7, 2022
Last Seen
May 7, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.