Description Summary
Conti was one of the most damaging ransomware operations in history, active from late 2019 until its public dissolution in mid-2022. It operated as a tightly-organized criminal enterprise with paid employees, HR processes, and office facilities. The group disbanded after publicly siding with Russia in the 2022 invasion of Ukraine, which triggered the leak of ~170,000 internal chat messages by a Ukrainian researcher. Many members migrated to Black Basta, BlackByte, Karakurt, Royal, and other successor brands.
Threat Actor
Russian-organized group that grew out of the Ryuk operation. Some operators are sanctioned by the U.S. and U.K.
Technical Indicators
Encryption Extension
.CONTI / .KREMLIN
Encryption Algorithm
ChaCha8 (file content) + RSA-4096 (key wrapping)
Ransom Note Name
readme.txt / R3ADM3.txt
Targeted Industries
Healthcare, Government, Manufacturing, Critical infrastructure
First Seen
December 2019
Last Seen
May 2022 (brand disbanded; operators migrated to successors)
Geographical Location
Worldwide; major impact in the United States, Costa Rica (national emergency declared)
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 4 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop | |
| T1486 | Data Encrypted for Impact (multi-threaded ChaCha8) |