Ransomware group profile · #20 by claimed victims
Conti ransomwarealso Wizard Spider, TrickBot gang, Conti Team
A ransomware-as-a-service operation run like a software company, with salaried staff, HR, code review and internal training material. Conti is the best-documented crew in existence: an unusually complete record of its internal correspondence survives, covering years of day-to-day operation alongside the training material issued to new operators.
Victimology
Who Conti claims to have breached, from 351 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Alliance Steel | Manufacturing | — | 7 Jun 2022 |
| LCRD | Not Found | — | 25 May 2022 |
| The Contact Company | Professional Services | — | 25 May 2022 |
| Central Restaurant Products | Agriculture and Food Production | — | 24 May 2022 |
| Schaumburg Park District | Government & Defense | — | 24 May 2022 |
| RateGain | Technology | — | 24 May 2022 |
| Imenco AS | Energy & Utilities | — | 23 May 2022 |
| Concepts in Millwork | Manufacturing | — | 23 May 2022 |
| Eurofred | Manufacturing | — | 23 May 2022 |
| Agile Sourcing Partners | Professional Services | — | 23 May 2022 |
| Alimentos y Frutos S.A. alimentos y frutos s.a. | Agriculture and Food Production | — | 23 May 2022 |
| Worksoft | Technology | — | 23 May 2022 |
All 351 Conti victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
14 MITRE ATT&CK techniques mapped to Conti from public advisories and VULONE's own analysis.
| Tactic | Technique | Procedure | Confidence |
|---|---|---|---|
| Initial Access | T1078 Valid Accounts | Bought or brute-forced RDP credentials and logged in directly. Conti also purchased access from brokers on the same forums this platform indexes. | Confirmed |
| Initial Access | T1566.001 Spearphishing Attachment | Phishing mail carrying a weaponised document that pulled BazarLoader or TrickBot, which then handed the host to Conti operators as a staging beachhead. | Confirmed |
| Execution | T1059.001 PowerShell | PowerShell used throughout, including to load Cobalt Strike beacons directly into memory and to disable defences before the encryptor ran. | Confirmed |
| Persistence | T1219 Remote Access Tools | Installed legitimate remote access software as a fallback channel, so losing the beacon did not lose the network. AnyDesk was the favourite; the manuals include… | Confirmed |
| Persistence | T1547.001 Registry Run Keys / Startup Folder | Run keys and scheduled tasks to survive reboot on the hosts used as staging points. | Reported |
| Credential Access | T1003.001 LSASS Memory | Mimikatz against LSASS to lift plaintext credentials and hashes, run immediately after gaining local admin. | Confirmed |
| Credential Access | T1558.003 Kerberoasting | Kerberoasting to pull service account tickets and crack them offline, a step the training manual walks through with the exact Invoke-Kerberoast invocation. | Confirmed |
| Discovery | T1018 Remote System Discovery | Network scanning for reachable hosts and shares, using off-the-shelf scanners rather than anything custom. | Confirmed |
| Discovery | T1087.002 Domain Account | ADFind and net commands to map the domain, its trusts and its administrators before moving. | Confirmed |
| Lateral Movement | T1021.002 SMB/Windows Admin Shares | SMB with stolen credentials to reach file servers and push the encryptor to admin shares. | Confirmed |
| Command and Control | T1071.001 Web Protocols | Cobalt Strike beacons over HTTPS with malleable profiles imitating ordinary web traffic, on rented infrastructure rotated between operations. | Confirmed |
| Exfiltration | T1567.002 Exfiltration to Cloud Storage | Rclone configured against MEGA and other cloud storage, run from the file server itself so the data never traversed a workstation. | Confirmed |
| Impact | T1486 Data Encrypted for Impact | AES-256 per file with an RSA-4096 wrapped key, run multithreaded across SMB shares. Large files were only partially encrypted so the run finished faster. | Confirmed |
| Impact | T1490 Inhibit System Recovery | Deleted volume shadow copies and disabled recovery before encrypting, so restore-in-place was not an option. | Confirmed |
Tooling observed
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Attack playbook
How a typical Conti intrusion unfolds, section by section.
Hosting and infrastructure
Rented, rotated, and paid for in crypto — Infrastructure was rented from bulletproof and ordinary providers alike, paid in cryptocurrency through intermediaries, and rotated between operations. The chat logs contain the provider names, the pricing, and complaint…
Beaconing and C2
Malleable profiles imitating ordinary web traffic — Cobalt Strike with malleable C2 profiles shaped to look like routine HTTPS. Operators were instructed to raise sleep intervals on sensitive hosts and to prefer SMB named-pipe beacons for machines with no direct egress, w…
Encryption
Fast enough to finish before anyone reacts — AES-256 per file with an RSA-4096 wrapped key. Up to 32 concurrent threads, and large files only partially encrypted, because the objective is to finish before an operator notices rather than to encrypt thoroughly. This …
Operational security
Rules the operators were given, and broke — Manuals prohibit working from a personal machine, require a VPN plus a jump host, and forbid reusing handles across forums. The record shows those rules being broken constantly, which is why the archive is so useful for …
Negotiation and extortion
Scripted, tiered, and researched — Negotiators worked from scripts with authority to discount along a defined ladder, and researched the victim's revenue and cyber insurance beforehand to set the initial demand. The chat logs contain both the scripts and …
Organisation
Run as a company — The internal record shows fixed salaries paid in bitcoin, working hours, performance reviews, an HR function that recruited on legitimate job boards, and staff who did not know what they were building. Teams were split b…
Frequently asked
Is Conti ransomware still active?
How many victims has Conti claimed?
Which industries does Conti target?
Which countries are most affected by Conti?
Where does VULONE get Conti victim data?
VULONE research mentioning Conti
Public sources
| Title | Publisher | Date |
|---|---|---|
| VULONE primary-source research | VULONE | 27 Feb 2022 |
| Conti Ransomware (AA21-265A) | CISA / FBI / NSA | 22 Sep 2021 |
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].