Aller au contenu principal
Retour à la base de rançongiciels
Groupe de rançongiciel

conti

Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang.

Victimes connues351

Niveau de menace

ÉLEVÉ

Tactiques, techniques et procédures (TTP)

CredentialTheft

  • Mimikatz
  • ProcDump
  • Router Scan
  • SharpChrome

DefenseEvasion

  • GMER
  • PCHunter

DiscoveryEnum

  • AdFind
  • Bloodhound
  • PowerView
  • Seatbelt
  • ShareFinder
  • +2 de plus

Exfiltration

  • Dropfiles
  • MEGA
  • Qaz[.]im
  • RClone
  • Sendspace
  • +1 de plus

LOLBAS

  • BITSAdmin
  • NTDS Utility (ntdsutil)
  • PsExec
  • WMIC

Offsec

  • Cobalt Strike
  • Metasploit
  • Meterpreter
  • PowerShell Empire
  • PowerSploit
  • +1 de plus

RMM-Tools

  • AnyDesk
  • Atera
  • Splashtop
0

Vérifier si vous êtes touché

Cherchez dans notre base si votre organisation figure sur la liste des victimes de conti.

Essayez maintenantGratuit⌘K
Exemple

score de risque · catégories de menace · sources · ancienneté · confiance — en une requête

Autres groupes de rançongiciel actifs