Conti Ransomware

Description Summary

Conti was one of the most damaging ransomware operations in history, active from late 2019 until its public dissolution in mid-2022. It operated as a tightly-organized criminal enterprise with paid employees, HR processes, and office facilities. The group disbanded after publicly siding with Russia in the 2022 invasion of Ukraine, which triggered the leak of ~170,000 internal chat messages by a Ukrainian researcher. Many members migrated to Black Basta, BlackByte, Karakurt, Royal, and other successor brands.

Threat Actor

Russian-organized group that grew out of the Ryuk operation. Some operators are sanctioned by the U.S. and U.K.

Technical Indicators

Encryption Extension
.CONTI / .KREMLIN
Encryption Algorithm
ChaCha8 (file content) + RSA-4096 (key wrapping)
Ransom Note Name
readme.txt / R3ADM3.txt
Targeted Industries
Healthcare, Government, Manufacturing, Critical infrastructure
First Seen
December 2019
Last Seen
May 2022 (brand disbanded; operators migrated to successors)
Geographical Location
Worldwide; major impact in the United States, Costa Rica (national emergency declared)

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 4 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
T1486 Data Encrypted for Impact (multi-threaded ChaCha8)