Overview

Platforms: Windows
Variants: Conti
Extensions: .CONTI
ATT&CK software: TrickBot, Ryuk, Conti, Bazar, Emotet, Cobalt Strike, Empire, LaZagne, Mimikatz, Diavol, GrimAgent · TrickBot, IcedID, Cobalt Strike, Rclone, Mimikatz, Router Scan · Cobalt Strike · PowerShell · Conti ransomware · BazarLoader · Mimikatz · Rclone · loader · Conti (S0575)
Initial access: T1566.001 · T1190 · Valid Accounts
Top countries: US · IE
Observed sectors: healthcare · Manufacturing · Food and drinks businesses · Retail & E-Commerce · Distribution
Tracked victims: 1,000

Victims

Alliance Steel CLAIMED
June 7, 2022 2 tracker sources
LCRD CLAIMED
May 25, 2022 2 tracker sources
The Contact Company CLAIMED
May 25, 2022 2 tracker sources
Central Restaurant Products CLAIMED
May 24, 2022 2 tracker sources
Schaumburg Park District CLAIMED
May 24, 2022 2 tracker sources
Show more victims (12)
RateGain CLAIMED
May 24, 2022 2 tracker sources
Pianca CLAIMED
May 23, 2022 2 tracker sources
Imenco AS CLAIMED
May 23, 2022 2 tracker sources
Concepts in Millwork CLAIMED
May 23, 2022 2 tracker sources
Eurofred CLAIMED
May 23, 2022 2 tracker sources
Agile Sourcing Partners CLAIMED
May 23, 2022 2 tracker sources
Alimentos y Frutos S.A. CLAIMED
May 23, 2022 2 tracker sources
Worksoft CLAIMED
May 23, 2022 2 tracker sources
Allcat Claims Service CLAIMED
May 23, 2022 2 tracker sources
Omicron Consulting S.r.L CLAIMED
May 23, 2022 IT Information Technologies Consulting 3 tracker sources
Information Technologies Consulting organization in IT.
FOR BlackCat and LockBit advert CLAIMED
May 17, 2022 2 tracker sources
For Costa Rica and US terrorists (Biden and his administration) CLAIMED
May 14, 2022 2 tracker sources

Operational Activity

Recent Observations

Active deployment of ransomware and data theft

TTPs

ATT&CK coverage: 24 techniques · 1 tactics
T1566.001 T1566.001
VERIFIED
Spearphishing Attachment
T1190 T1190
VERIFIED
Exploit Public-Facing Application
T1059.003 T1059.003
VERIFIED
Windows Command Shell
Show more TTPs (21)
T1106 T1106
VERIFIED
Native API
T1140 T1140
VERIFIED
Deobfuscate/Decode Files or Information
T1027 T1027
VERIFIED
Obfuscated Files or Information
T1055.001 T1055.001
VERIFIED
Dynamic-link Library Injection
T1083 T1083
VERIFIED
File and Directory Discovery
T1135 T1135
VERIFIED
Network Share Discovery
T1057 T1057
VERIFIED
Process Discovery
T1016 T1016
VERIFIED
System Network Configuration Discovery
T1049 T1049
VERIFIED
System Network Connections Discovery
T1021.002 T1021.002
VERIFIED
SMB/Windows Admin Shares
T1080 T1080
VERIFIED
Taint Shared Content
T1486 T1486
VERIFIED
Data Encrypted for Impact
T1490 T1490
VERIFIED
Inhibit System Recovery
T1489 T1489
VERIFIED
Service Stop
T1562.001 T1562.001
VERIFIED
Disabling Windows Defender via Set-MpPreference -DisableRealtimeMonitoring
T1003.003 T1003.003
VERIFIED
NTDS.dit extraction using vssadmin to create shadow copies and copy the file.
T1482 T1482
VERIFIED
Domain trust discovery using nltest.
T1018 T1018
VERIFIED
Remote system discovery using net view and net user commands.
T1567.002 T1567.002
VERIFIED
Data exfiltration via Rclone to cloud storage (Mega/FTP).
T1078 Valid Accounts
VERIFIED
Initial Access
Conti actors were observed gaining unauthorized access through stolen RDP credentials.
T1566.002 Spearphishing Link
VERIFIED
Initial Access
Malicious phishing links were documented as part of TrickBot-based Conti delivery chains.

CVEs

Windows Netlogon Elevation of Privilege Vulnerability (Zerologon); exploited by Conti actors for privilege escalation and lateral movement per leaked playbook and CISA advisory.
Windows Print Spooler Remote Code Execution Vulnerability (PrintNightmare); exploited by Conti actors for privilege escalation and lateral movement per leaked playbook and CISA advisory.
Microsoft Windows Server Message Block 1.0 server vulnerabilities (EternalBlue/MS17-010); referenced in Conti playbook and CISA advisory for privilege escalation/lateral movement.
Show more CVEs (15)
Apache Log4j Remote Code Execution (Log4Shell); Conti observed exploiting this (and related Log4j CVEs CVE-2021-45046, CVE-2021-45105) for initial access, including to vCenter servers.
Fortinet FortiOS Path Traversal/Arbitrary File Read Vulnerability; exploited by Conti for initial access (e.g., FortiGate firewalls) per Sophos DFIR, Tenable, and ContiLeaks analysis.
Fortinet FortiOS Improper Access Control Vulnerability; exploited by Conti for initial access per Sophos DFIR and Tenable ContiLeaks analysis.
Windows SMBv3 Client/Server Remote Code Execution (SMBGhost); listed in ContiLeaks as initial access vulnerability used by group/affiliates.
Windows Remote Desktop Gateway Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
Microsoft Exchange Validation Key Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
VMware vSphere Client Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
VMware vSphere Client Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
VMware vCenter Server Remote Code Execution; listed in ContiLeaks as initial access vulnerability.
Microsoft Exchange Server Remote Code Execution (ProxyLogon); listed in ContiLeaks as initial access vulnerability.
Windows Background Intelligent Transfer Service Elevation of Privilege (HiveNightmare/SeriousSAM); listed in Group-IB report and ContiLeaks for privilege escalation.
Windows InstallerFileTakeOver Local Privilege Escalation; listed in Group-IB report for privilege escalation.
Zerologon exploit variant or related; listed in Group-IB for privilege escalation.
BitsArbitraryFileMove Local Privilege Escalation; listed in Group-IB report for privilege escalation.
Related to BitsArbitraryFileMove; listed in Group-IB for privilege escalation.

Infrastructure

Data Leak Site (DLS)
leak_site
HISTORICAL
Exfiltration endpoint
Cloud storage service used by Conti operators for data exfiltration.

Attribution

Wizard Spider VERIFIED
other

Affiliates

Affiliate program identified. Conti operated as a ransomware-as-a-service model involving affiliates/deployers, but with a structure that differed from a typical affiliate program. Reporting indicates deployers were likely wage-paid, while other U.S. government reporting describes profit-sharing between RaaS owners and affiliates.

Timeline

2022-06
Public infrastructure shut down
The remaining Conti data leak and ransom negotiation infrastructure was taken offline.
2022-05
Conti operation begins shutdown
The operation began decommissioning internal infrastructure and retiring the Conti brand.
2022-02
More than 1,000 reported attacks
U.S. authorities reported that Conti attacks against U.S. and international organizations had exceeded 1,000.
Show more events (5)
2021-08-05
Leaking of Conti training material by 'm1Geelka'.
2021-06
Massive recruitment campaign on XSS forum by 'IT_Work'.
2021-05
Attack on Ireland healthcare system
2021-05
Ireland HSE attack
Conti ransomware caused major disruption to Ireland's national Health Service Executive.
2019-12
Conti first observed
Conti ransomware activity was first observed in late 2019.

Sources

Conti
MITRE ATT&CK
Framework
Wizard Spider
MITRE ATT&CK
Framework
Conti Ransomware
CISA, FBI, NSA
Show more sources (22)
Conti Ransomware Gang: An Overview
Palo Alto Networks Unit 42
Conti Ransomware
Cyber Swachhta Kendra