conti
1 incidentes
1 paises
1 sectores
ransomware RU Ultimo: 2026-06-25
Aliases: Wizard Spider, Gold Ulrick, UNC1878
Conti was a Russia-based ransomware-as-a-service (RaaS) operation that emerged in December 2019, initially operating under the alias Wizard Spider, and is believed to have evolved from the Ryuk ransomware strain. The group's primary motivation was financial gain through cyberattacks and data extortion, generating an estimated $180 million in 2021. Conti distinguished itself through its rapid, multi-threaded data encryption, its adoption of a fixed-wage model for affiliates rather than commission, and its aggressive double extortion tactics. The group was highly organized, often described as operating like a modern corporation. Conti's public allegiance to Russia during the 2022 invasion of Ukraine led to internal chat logs and tools being leaked, contributing significantly to its eventual disbandment in May 2022, though former members subsequently migrated to other cybercrime groups.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
Andorra
United Arab EmiratesAlbania
ArmeniaAngola
Argentina
Austria
Australia
AzerbaijanBosnia and Herzegovina
Sectores atacados
Government (1)
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingRail TransportationSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturing
URLs nuevas detectadas en IntelTracker