← All ransomware groups

Ransomware group profile · #20 by claimed victims

Conti ransomwarealso Wizard Spider, TrickBot gang, Conti Team

A ransomware-as-a-service operation run like a software company, with salaried staff, HR, code review and internal training material. Conti is the best-documented crew in existence: an unusually complete record of its internal correspondence survives, covering years of day-to-day operation alongside the training material issued to new operators.

Defunct Russia First seen Feb 2020 ATT&CK G0102 AES-256 per file, RSA-4096 wrapped key; multithreaded, partial encryption on large files Russian
351Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
6Countries hit
8Leak-site URLs tracked, 0 online
7 Jun 2022Latest claim recorded

Victimology

Who Conti claims to have breached, from 351 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Manufacturing91
Professional Services61
Retail & E-Commerce30
Technology20
Healthcare19
Agriculture and Food Production17
Financial Services16
Transportation12

Top countries

United States12
Canada2
Italy2
Ireland1
United Kingdom1
Thailand1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
Alliance Steel Manufacturing 7 Jun 2022
LCRD Not Found 25 May 2022
The Contact Company Professional Services 25 May 2022
Central Restaurant Products Agriculture and Food Production 24 May 2022
Schaumburg Park District Government & Defense 24 May 2022
RateGain Technology 24 May 2022
Imenco AS Energy & Utilities 23 May 2022
Concepts in Millwork Manufacturing 23 May 2022
Eurofred Manufacturing 23 May 2022
Agile Sourcing Partners Professional Services 23 May 2022
Alimentos y Frutos S.A. alimentos y frutos s.a. Agriculture and Food Production 23 May 2022
Worksoft Technology 23 May 2022

All 351 Conti victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

14 MITRE ATT&CK techniques mapped to Conti from public advisories and VULONE's own analysis.

TacticTechniqueProcedureConfidence
Initial Access T1078 Valid Accounts Bought or brute-forced RDP credentials and logged in directly. Conti also purchased access from brokers on the same forums this platform indexes. Confirmed
Initial Access T1566.001 Spearphishing Attachment Phishing mail carrying a weaponised document that pulled BazarLoader or TrickBot, which then handed the host to Conti operators as a staging beachhead. Confirmed
Execution T1059.001 PowerShell PowerShell used throughout, including to load Cobalt Strike beacons directly into memory and to disable defences before the encryptor ran. Confirmed
Persistence T1219 Remote Access Tools Installed legitimate remote access software as a fallback channel, so losing the beacon did not lose the network. AnyDesk was the favourite; the manuals include… Confirmed
Persistence T1547.001 Registry Run Keys / Startup Folder Run keys and scheduled tasks to survive reboot on the hosts used as staging points. Reported
Credential Access T1003.001 LSASS Memory Mimikatz against LSASS to lift plaintext credentials and hashes, run immediately after gaining local admin. Confirmed
Credential Access T1558.003 Kerberoasting Kerberoasting to pull service account tickets and crack them offline, a step the training manual walks through with the exact Invoke-Kerberoast invocation. Confirmed
Discovery T1018 Remote System Discovery Network scanning for reachable hosts and shares, using off-the-shelf scanners rather than anything custom. Confirmed
Discovery T1087.002 Domain Account ADFind and net commands to map the domain, its trusts and its administrators before moving. Confirmed
Lateral Movement T1021.002 SMB/Windows Admin Shares SMB with stolen credentials to reach file servers and push the encryptor to admin shares. Confirmed
Command and Control T1071.001 Web Protocols Cobalt Strike beacons over HTTPS with malleable profiles imitating ordinary web traffic, on rented infrastructure rotated between operations. Confirmed
Exfiltration T1567.002 Exfiltration to Cloud Storage Rclone configured against MEGA and other cloud storage, run from the file server itself so the data never traversed a workstation. Confirmed
Impact T1486 Data Encrypted for Impact AES-256 per file with an RSA-4096 wrapped key, run multithreaded across SMB shares. Large files were only partially encrypted so the run finished faster. Confirmed
Impact T1490 Inhibit System Recovery Deleted volume shadow copies and disabled recovery before encrypting, so restore-in-place was not an option. Confirmed

Tooling observed

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Attack playbook

How a typical Conti intrusion unfolds, section by section.

Hosting and infrastructure

Rented, rotated, and paid for in crypto — Infrastructure was rented from bulletproof and ordinary providers alike, paid in cryptocurrency through intermediaries, and rotated between operations. The chat logs contain the provider names, the pricing, and complaint…

Beaconing and C2

Malleable profiles imitating ordinary web traffic — Cobalt Strike with malleable C2 profiles shaped to look like routine HTTPS. Operators were instructed to raise sleep intervals on sensitive hosts and to prefer SMB named-pipe beacons for machines with no direct egress, w…

Encryption

Fast enough to finish before anyone reacts — AES-256 per file with an RSA-4096 wrapped key. Up to 32 concurrent threads, and large files only partially encrypted, because the objective is to finish before an operator notices rather than to encrypt thoroughly. This …

Operational security

Rules the operators were given, and broke — Manuals prohibit working from a personal machine, require a VPN plus a jump host, and forbid reusing handles across forums. The record shows those rules being broken constantly, which is why the archive is so useful for …

Negotiation and extortion

Scripted, tiered, and researched — Negotiators worked from scripts with authority to discount along a defined ladder, and researched the victim's revenue and cyber insurance beforehand to set the initial demand. The chat logs contain both the scripts and …

Organisation

Run as a company — The internal record shows fixed salaries paid in bitcoin, working hours, performance reviews, an HR function that recruited on legitimate job boards, and staff who did not know what they were building. Teams were split b…

Frequently asked

Is Conti ransomware still active?
Conti is tracked as defunct. The most recent leak-site claim VULONE recorded is dated 7 June 2022.
How many victims has Conti claimed?
VULONE has recorded 351 leak-site victim claims attributed to Conti since July 2020, across 6 countries and 14 sectors.
Which industries does Conti target?
The sectors most often named on the Conti leak site are Manufacturing, Professional Services, Retail & E-Commerce.
Which countries are most affected by Conti?
Most Conti victims recorded by VULONE are located in United States, Canada, Italy.
Where does VULONE get Conti victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

VULONE research mentioning Conti

Public sources

TitlePublisherDate
VULONE primary-source researchVULONE27 Feb 2022
Conti Ransomware (AA21-265A)CISA / FBI / NSA22 Sep 2021

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].