Conti

Inactive
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.
351 Victims
Jul 30, 2020 First Discovered
Jun 7, 2022 Last Discovered
1562 Days Inactive
0% Infostealer
0/3 Sites Online
Known Locations (3)
Error Response Page
continews.bz
CONTI.News
continewsnv5otx5kaoje7krkto2qbu3gtqef22mnr7eaxw3y6ncz3ad.onion
continews.click | 522: Connection timed out
continews.click
Tools Used
CredentialTheft
Mimikatz, ProcDump, Router Scan, SharpChrome
DefenseEvasion
GMER, PCHunter
DiscoveryEnum
AdFind, Bloodhound, PowerView, Seatbelt, ShareFinder, SharpView, SoftPerfect NetScan
Exfiltration
Dropfiles, MEGA, Qaz[.]im, RClone, Sendspace, WinSCP
LOLBAS
BITSAdmin, NTDS Utility (ntdsutil), PsExec, WMIC
Offsec
Cobalt Strike, Metasploit, Meterpreter, PowerShell Empire, PowerSploit, Rubeus
RMM-Tools
AnyDesk, Atera, Splashtop
Intelligence
Victims (351)

Detailed victim list temporarily unavailable

This group has 351 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.