Conti
Aliases: Conti ransomware
Source profile review date: 2026-06-01
Added to the source registry: 2020-07-31 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.
Executive summary
Conti was a large RaaS operation that CISA/FBI/NSA/USSS linked to TrickBot, IcedID, Cobalt Strike, malicious Word attachments and hundreds of attacks.
Conti is historical but highly valuable as a defensive dossier: phishing, malware loaders, Cobalt Strike, fast lateral movement, privilege use and large-scale impact form an attack chain that still returns in successor groups.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Executive summary
Conti is one of the most important historical ransomware profiles because the operation showed at scale how professional RaaS can work. CISA, FBI, NSA and USSS published AA21-265A with indicators and TTPs, including malicious Word attachments that can download or drop TrickBot, IcedID and/or Cobalt Strike to enable lateral movement and later phases toward Conti deployment.
For visitors, Conti is mainly useful as a model for modern ransomware chains. The name itself is historical, but the method lives on: phishing, loader, command-and-control, credential access, lateral movement, data exfiltration and impact.
The key policy translation is that prevention must work in layers. Mail security alone is not enough, MFA alone is not enough and backups alone are not enough. Conti showed how fast an attack moves through phases when one control fails and the next controls are missing.
Group and development
Conti was regarded as a RaaS model with professional organisation, affiliates and negotiations. The group targeted critical infrastructure and other organisations under high pressure to recover.
Conti is also important because of its connection to malware ecosystems. TrickBot and IcedID were not just standalone malware families; they could act as access paths toward ransomware. A loader infection must therefore be treated as possible ransomware preparation.
The profile must be both historical and practical. The goal is not to say Conti has exactly the same form today, but to show how a ransomware chain runs from first email to business impact.
Attack pattern from public cases
The advisory describes malicious Word attachments with embedded scripts that can download or drop malware such as TrickBot, IcedID and/or Cobalt Strike. This is a clear chain: phishing opens the door, the loader builds access, Cobalt Strike or comparable tooling supports lateral movement, and ransomware follows later.
After initial access, the issue is speed and privilege. Look for credential dumping, PowerShell, remote services, Cobalt Strike beacons, new services and admin-share use.
Data exfiltration and double extortion are part of the model. Check staging, compression, cloud transfer, outbound volume and access to sensitive shares. Encryption is the visible final phase, not the first damage.
Known IOCs and artefacts
TrickBot, IcedID and Cobalt Strike are core artefacts in the Conti advisory context. A hit on one of these components must be escalated to ransomware preparation until proven otherwise.
Malicious Word attachments with embedded scripts are a concrete initial-access pattern. Look for Office child processes, script execution, downloaders and unexpected network connections from user context.
Conti IOCs from AA21-265A are useful for retro-hunting. Also use behavioural detection from loader to lateral movement, because hashes and infrastructure age.
Practical detection logic
Create a chain detection from Office to loader to beacon. Word or Excel starting scripts, downloading a payload and then causing Cobalt Strike-like traffic must be treated as high risk.
After every TrickBot or IcedID hit, check whether domain discovery, credential dumping, remote service creation or RDP follows. Without that check, a possible ransomware path remains open.
Look for rapid privilege escalation: new domain admins, group-policy changes, service accounts logging in interactively and admin shares accessed from unusual hosts.
Concrete hardening priorities
Treat Conti not as only a malware name, but as an attack chain. The first visible indicator can be a ransom note, but the defensible phases are earlier: external access, credential abuse, discovery, data staging, exfiltration and disruption of recovery resources.
Store logs centrally for identity, VPN, EDR, firewall, Windows Event Logs, remote access and backup platforms. Local logs are useful, but ransomware reconstruction must remain outside the actor’s reach.
Test recovery as if domain credentials are compromised. Backups, hypervisors and storage administration must be protected with separate accounts and network paths.
Block or restrict Office macro and script execution from internet documents. Combine this with sandboxing, EDR and user training, but do not rely on awareness alone.
Treat loader infections as pre-ransomware. Credential reset, host isolation and hunting for lateral movement should be standard response steps.
Identity, naming and attribution
For Conti, the operational starting point is an exact identity match. The local dossier records the following names or aliases: Conti ransomware. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.
Timeline and interpretation of dates
The source registry date available for Conti is 2020-07-31; the metadata snapshot was collected on 2026-09-15. These timestamps describe the available record, not a proven beginning of criminal operations. Registration may follow earlier activity, and a claim can concern an older incident. A defensible timeline separates suspected intrusion, data access, discovery by the victim, publication by the claimant and discovery by the monitoring service. The profile review date is another independent timestamp. Analysts should not silently convert one date into another. When sources disagree, preserve both observations and their provenance, then explain the uncertainty rather than presenting a falsely precise attack chronology.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| malware | TrickBot | CISA AA21-265A | Kan via malicious Word attachments worden gedownload of gedropt in Conti-keten. |
| malware | IcedID | CISA AA21-265A | Loader genoemd in Conti-advisorycontext. |
| tooling | Cobalt Strike | CISA AA21-265A | Gebruikt voor laterale beweging en latere fases. |
| access | malicious Word attachments with embedded scripts | CISA AA21-265A | Initiële toegang en malwaredelivery. |
Sources
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.