Overview
Platforms:
Windows
Variants:
Conti
Extensions:
.CONTI
ATT&CK software:
TrickBot, Ryuk, Conti, Bazar, Emotet, Cobalt Strike, Empire, LaZagne, Mimikatz, Diavol, GrimAgent · TrickBot, IcedID, Cobalt Strike, Rclone, Mimikatz, Router Scan · Cobalt Strike · PowerShell · Conti ransomware · BazarLoader · Mimikatz · Rclone · loader · Conti (S0575)
Initial access:
T1566.001 · T1190 · Valid Accounts
Top countries:
US · IE
Observed sectors:
healthcare · Manufacturing · Food and drinks businesses · Retail & E-Commerce · Distribution
Tracked victims:
1,000
Victims
Alliance Steel
CLAIMED
LCRD
CLAIMED
The Contact Company
CLAIMED
Central Restaurant Products
CLAIMED
Schaumburg Park District
CLAIMED
Show more victims (12)
RateGain
CLAIMED
Pianca
CLAIMED
Imenco AS
CLAIMED
Concepts in Millwork
CLAIMED
Eurofred
CLAIMED
Agile Sourcing Partners
CLAIMED
Alimentos y Frutos S.A.
CLAIMED
Worksoft
CLAIMED
Allcat Claims Service
CLAIMED
Omicron Consulting S.r.L
CLAIMED
Information Technologies Consulting organization in IT.
FOR BlackCat and LockBit advert
CLAIMED
For Costa Rica and US terrorists (Biden and his administration)
CLAIMED
Operational Activity
Recent Observations
Active deployment of ransomware and data theft
TTPs
ATT&CK coverage:
24 techniques
· 1 tactics
T1566.001
T1566.001
VERIFIEDSpearphishing Attachment
T1190
T1190
VERIFIEDExploit Public-Facing Application
T1059.003
T1059.003
VERIFIEDWindows Command Shell
Show more TTPs (21)
T1106
T1106
VERIFIEDNative API
T1140
T1140
VERIFIEDDeobfuscate/Decode Files or Information
T1027
T1027
VERIFIEDObfuscated Files or Information
T1055.001
T1055.001
VERIFIEDDynamic-link Library Injection
T1083
T1083
VERIFIEDFile and Directory Discovery
T1135
T1135
VERIFIEDNetwork Share Discovery
T1057
T1057
VERIFIEDProcess Discovery
T1016
T1016
VERIFIEDSystem Network Configuration Discovery
T1049
T1049
VERIFIEDSystem Network Connections Discovery
T1021.002
T1021.002
VERIFIEDSMB/Windows Admin Shares
T1080
T1080
VERIFIEDTaint Shared Content
T1486
T1486
VERIFIEDData Encrypted for Impact
T1490
T1490
VERIFIEDInhibit System Recovery
T1489
T1489
VERIFIEDService Stop
T1562.001
T1562.001
VERIFIEDDisabling Windows Defender via Set-MpPreference -DisableRealtimeMonitoring
T1003.003
T1003.003
VERIFIEDNTDS.dit extraction using vssadmin to create shadow copies and copy the file.
T1482
T1482
VERIFIEDDomain trust discovery using nltest.
T1018
T1018
VERIFIEDRemote system discovery using net view and net user commands.
T1567.002
T1567.002
VERIFIEDData exfiltration via Rclone to cloud storage (Mega/FTP).
T1078
Valid Accounts
VERIFIEDInitial Access
Conti actors were observed gaining unauthorized access through stolen RDP credentials.
T1566.002
Spearphishing Link
VERIFIEDInitial Access
Malicious phishing links were documented as part of TrickBot-based Conti delivery chains.
CVEs
Windows Netlogon Elevation of Privilege Vulnerability (Zerologon); exploited by Conti actors for privilege escalation and lateral movement per leaked playbook and CISA advisory.
Windows Print Spooler Remote Code Execution Vulnerability (PrintNightmare); exploited by Conti actors for privilege escalation and lateral movement per leaked playbook and CISA advisory.
Microsoft Windows Server Message Block 1.0 server vulnerabilities (EternalBlue/MS17-010); referenced in Conti playbook and CISA advisory for privilege escalation/lateral movement.
Show more CVEs (15)
Apache Log4j Remote Code Execution (Log4Shell); Conti observed exploiting this (and related Log4j CVEs CVE-2021-45046, CVE-2021-45105) for initial access, including to vCenter servers.
Fortinet FortiOS Path Traversal/Arbitrary File Read Vulnerability; exploited by Conti for initial access (e.g., FortiGate firewalls) per Sophos DFIR, Tenable, and ContiLeaks analysis.
Fortinet FortiOS Improper Access Control Vulnerability; exploited by Conti for initial access per Sophos DFIR and Tenable ContiLeaks analysis.
Windows SMBv3 Client/Server Remote Code Execution (SMBGhost); listed in ContiLeaks as initial access vulnerability used by group/affiliates.
Windows Remote Desktop Gateway Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
Microsoft Exchange Validation Key Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
VMware vSphere Client Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
VMware vSphere Client Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
VMware vCenter Server Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
Microsoft Exchange Server Remote Code Execution (ProxyLogon); listed in ContiLeaks as initial access vulnerability.
Windows Background Intelligent Transfer Service Elevation of Privilege (HiveNightmare/SeriousSAM); listed in Group-IB report and ContiLeaks for privilege escalation.
Windows InstallerFileTakeOver Local Privilege Escalation; listed in Group-IB report for privilege escalation.
Zerologon exploit variant or related; listed in Group-IB for privilege escalation.
BitsArbitraryFileMove Local Privilege Escalation; listed in Group-IB report for privilege escalation.
Related to BitsArbitraryFileMove; listed in Group-IB for privilege escalation.
Infrastructure
Data Leak Site (DLS)
leak_site
HISTORICAL
Exfiltration endpoint
Cloud storage service used by Conti operators for data exfiltration.
Attribution
Wizard Spider
VERIFIED
other
Affiliates
Affiliate program identified. Conti operated as a ransomware-as-a-service model involving affiliates/deployers, but with a structure that differed from a typical affiliate program. Reporting indicates deployers were likely wage-paid, while other U.S. government reporting describes profit-sharing between RaaS owners and affiliates.
Timeline
2022-06
Public infrastructure shut down
The remaining Conti data leak and ransom negotiation infrastructure was taken offline.
2022-05
Conti operation begins shutdown
The operation began decommissioning internal infrastructure and retiring the Conti brand.
2022-02
More than 1,000 reported attacks
U.S. authorities reported that Conti attacks against U.S. and international organizations had exceeded 1,000.
Show more events (5)
2021-08-05
Leaking of Conti training material by 'm1Geelka'.
2021-06
Massive recruitment campaign on XSS forum by 'IT_Work'.
2021-05
Attack on Ireland healthcare system
2021-05
Ireland HSE attack
Conti ransomware caused major disruption to Ireland's national Health Service Executive.
2019-12
Conti first observed
Conti ransomware activity was first observed in late 2019.
Sources
Conti Ransomware
CISA, FBI, NSA
Show more sources (22)
Conti cyber attack on the HSE — Independent Post Incident Review
Health Service Executive
Incident report
Conti Ransomware Gang: An Overview
Palo Alto Networks Unit 42
Conti Ransomware
Cyber Swachhta Kendra
Conti Ransomware
CISA
Conti Ransomware
Qualys
Reward for Information: Owners/Operators/Affiliates of the Conti Ransomware as a Service (RaaS)
U.S. Department of State
Conti ransomware threat group adopts Log4j exploit to compromise VMware vCenter servers
Broadcom Inc.
Threat intelligence
Ireland's Health Service Executive ransomware attack (2021)
Cyber Law Toolkit