Description
Conti is a Russian based ransomware as a service group that became one of the most prolific extortion operations in the world before its collapse. Its affiliates compromised large organizations through phishing, credential theft, and exploitation of perimeter services, exfiltrated data, and demanded multi million dollar ransoms. A disgruntled affiliate leaked its source code and internal chat logs in 2021, exposing internal operations, and the group dissolved in 2022 as its members moved to successor operations.
Stats
- First seen
- March 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
16 techniques across 5 tactics.
TA0005 Stealth
TA0007 Discovery
TA0008 Lateral Movement
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.Conti.103 |
| Gen:Variant.Ransom.Conti.119 |
| Gen:Variant.Ransom.Conti.13 |
| Gen:Variant.Ransom.Conti.135 |
| Gen:Variant.Ransom.Conti.143 |
| Gen:Variant.Ransom.Conti.160 |
| Gen:Variant.Ransom.Conti.22 |
| Gen:Variant.Ransom.Conti.33 |
| Gen:Variant.Ransom.Conti.47 |
| Gen:Variant.Ransom.Conti.59 |







