Uptime Hamster: 21d 6h 2mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza conti

conti

1 incidentes 1 paises 1 sectores threat-actor RU Ultimo: 2026-06-29
Aliases: Wizard Spider, Gold Ulrick, UNC1878, Putter Panda, PLA Unit 61486, TG-6952, técnicas, G0023, ELMER backdoor, Gh0st, HTRAN, UNICAT, Poison Ivy, Pandora, Trochilus RAT, PlugX, EvilGrab, 3102 variant of 9002 RAT
Ver en IntelTracker → APTTrail →
Conti was a Russia-based ransomware-as-a-service (RaaS) operation that emerged in December 2019, initially operating under the alias Wizard Spider, and is believed to have evolved from the Ryuk ransomware strain. The group's primary motivation was financial gain through cyberattacks and data extortion, generating an estimated $180 million in 2021. Conti distinguished itself through its rapid, multi-threaded data encryption, its adoption of a fixed-wage model for affiliates rather than commission, and its aggressive double extortion tactics. The group was highly organized, often described as operating like a modern corporation. Conti's public allegiance to Russia during the 2022 invasion of Ukraine led to internal chat logs and tools being leaked, contributing significantly to its eventual disbandment in May 2022, though former members subsequently migrated to other cybercrime groups.

Aliases del actor

Wizard SpiderGold UlrickUNC1878Putter PandaPLA Unit 61486TG-6952técnicasG0023ELMER backdoorGh0stHTRANUNICATPoison IvyPandoraTrochilus RATPlugXEvilGrab3102 variant of 9002 RATSeven Pointed Daggerotroslo que sugiere una amplia gama de herramientastécnicas utilizadas en operaciones de amenaza a largo plazoG0062NetTravelerZeroTPCratShadow NetworkSabPubTA413 (Proofpoint)ENDTRADESoutheast AsiaItaDuke

Actores similares

Operation DRBControlapt · 0[Unnamed group]apt · 0Conquerors Electronic Armyapt · 0Operation Red Signatureapt · 0Predator Pandaapt · 0Eloquent Pandaapt · 0Operation Olympic Gamesapt · 0LUNAR SPIDERapt · 0Turla Groupapt · 0Operation SLOW#TEMPESTapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupransomware.anggipradana.comRansomware Group: conti
DLS / leak siteunknownnitter.netIdo Cohen: We continue to monitor additional sources in the darknet. Here are some of the events that were added to our platform in the last week. 1 A major breach exposed over 500GB of sensitive personal information from job seekers, posing a high risk of identity theft and fraud. 2 Remote access to POS systems is being sold, threatening financial data and sensitive customer information across large retail businesses globally.
X/Twitterupx.comIdo Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.
DLS / leak siteunknownnitter.netIdo Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.
DLS / leak siteunknownnitter.netIdo Cohen: The Icarus supply chain extortion campaign continues to unfold. The group has now added 5 additional victims, all with their identities partially concealed. The guessing game has officially begun. How many organizations were impacted through this supply chain incident? And are we witnessing the emergence of a serious competitor to CLOP in the supply chain extortion arena? We'll know more soon.
DLS / leak siteunknownnitter.netIdo Cohen: APT73 continues to expand its operations. The group has added 3 new victims to its leak site, including a government entity in South America and a major international airport operator in Central Europe serving tens of millions of passengers annually. APT73 was added to the DarkFeed platform in mid-2024 and has since claimed 110+ victims.
DLS / leak siteupnitter.netIdo Cohen: Weekly Ransomware & Cyber Extortion Intelligence Report Our platform continuously monitors ransomware groups and darknet activity worldwide.
DLS / leak siteunknownwww.breachsense.comvendrig.nl - Conti Data Breach
DLS / leak siteunknownduckduckgo.comvendrig.nl - Conti Data Breach
DLS / leak siteunknownduckduckgo.comvendrig.nl - Conti Data Breach
DLS / leak siteunknownwww.breachsense.comwww.nutrisa.com - Conti Data Breach
DLS / leak siteunknownduckduckgo.comwww.nutrisa.com - Conti Data Breach
DLS / leak siteunknownduckduckgo.comwww.nutrisa.com - Conti Data Breach
DLS / leak siteupwww.breachsense.comturla.it - Conti Data Breach
DLS / leak siteupduckduckgo.comturla.it - Conti Data Breach
DLS / leak siteupduckduckgo.comturla.it - Conti Data Breach
DLS / leak siteunknownwww.breachsense.comjamacfoods.com - Conti Data Breach
DLS / leak siteunknownduckduckgo.comjamacfoods.com - Conti Data Breach
DLS / leak siteunknownduckduckgo.comjamacfoods.com - Conti Data Breach
DLS / leak siteunknownwww.breachsense.commarquezbrothers.com - Conti Data Breach
DLS / leak siteunknownduckduckgo.commarquezbrothers.com - Conti Data Breach
DLS / leak siteunknownduckduckgo.commarquezbrothers.com - Conti Data Breach
DLS / leak siteunknowngetbootstrap.comgarequipment.com - Conti Data Breach
Repositoriounknowngithub.comgarequipment.com - Conti Data Breach
DLS / onionofflinecontinewsnv5otx5kaoje7krkto2qbu3gtqef22mnr7eaxw3y6ncz3ad.onionCTI.FYI
Webofflinecontinews.clickCTI.FYI
Webofflinecontinews.bzCTI.FYI
DLS / leak siteunknownwww.cisa.govOSINT
DLS / leak siteunknownthedfirreport.comOSINT
DLS / leak siteunknownthedfirreport.comOSINT
Malware asociado
NetSupport, Bazar, Emotet, win.lockfile, BatLoader, Mimikatz
Tecnicas MITRE
T1018, T1552.006, T1547.001, T1553.002, T1074.001, T1480
CVEs relacionadas
CVE-2025-23121, CVE-2025-23120, CVE-2024-4577, CVE-2024-40711, CVE-2024-26169, CVE-2023-41570
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

AndorraUnited Arab EmiratesAlbaniaArmeniaAngolaArgentinaAustriaAustraliaAzerbaijanBosnia and Herzegovina

Sectores atacados

Government (1)

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingRail TransportationSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com