216.73.216.36

Threat Profile: Conti Ransomware Group

· Published 30/09/2025 05:15 · Modified 30/09/2025 08:41

Export JSON

Essential information

Published
30/09/2025 05:15
Modified
30/09/2025 08:41
Tags
2025-09-30 cobalt strike conti critical-infrastructure double-extortion education government healthcare ransomware russia-based ryuk trickbot wizard spider
Related entities
2 observables, 1 intrusion sets (apt), 14 techniques (mitre), 6 malware, 7 others

Description

, a notorious operation identified in 2019, quickly gained infamy for its advanced encryption, rapid lateral movement, and double extortion tactics. Operated by the group, evolved from and maintained suspected ties to Russian state interests. Between 2019 and 2022, targeted providers, governments, educational institutions, critical infrastructure, and private businesses, earning an estimated $180 million in 2021. Their aggressive tactics highlighted the urgent need for strong cybersecurity defenses. In 2022, internal divisions arose following leaked private chats. 's operations mimicked legitimate businesses, showcasing the industrialization of cybercrime and its devastating impact on critical sectors.

External references