ContFR
0 incidentes
0 paises
0 sectores
ransomware FR Ultimo: -
ContFR, commonly known as the Conti ransomware group, emerged in December 2019 and is understood to be operated by the Russia-based hacking group 'Wizard Spider'. Initially observed under this pseudonym, Conti rapidly evolved into a prolific Ransomware-as-a-Service (RaaS) operation, distinguished by its unique affiliate payment model where deployers received fixed wages rather than a percentage of ransom payments. The group's primary motivation was financial gain through extensive cyberattacks and data extortion. Conti gained notoriety for its exceptionally fast, multi-threaded encryption using AES-256 and its aggressive double extortion tactics, which involved encrypting victims' data and threatening to publish exfiltrated sensitive information on a dedicated leak site. While the Conti brand formally dissolved around May 2022, its underlying codebases, operational methodologies, and some members subsequently splintered and influenced other significant ransomware ecosystems.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
Costa Rica
Ireland
Netherlands
New Zealand
PeruTaiwan, Province of China
United States
Sectores objetivo (SOCRadar)
Energy & Utilities ManufacturingRetailInformation ServicesEducational ServicesHealthCare & Social AssistancePublic AdministrationTelecommunicationsInsuranceJustice & Safety Activities