Conti is a Russia-linked ransomware group known for fast encryption and aggressive double extortion tactics.
Analyst brief
Conti is a Russia-linked ransomware operated by the Wizard Spider cybercrime group, known for its fast encryption and rapid lateral movement across networks. It primarily targets organizations with high financial liquidity, notably in healthcare, government, and manufacturing sectors, employing a 'double extortion' model. The group uses aggressive, manual TTPs with tools like Cobalt Strike and often gains initial access via phishing or compromised RDP. Defenders should focus on network segmentation, securing RDP endpoints, and blocking initial access vectors such as phishing emails.
conti
crime
Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.