OAK — OnChain Attack Knowledge

Software · OAK-S26 · ransomware

OAK-S26 — Conti ransomware

Type
ransomware
Aliases
Conti (the operator-side and leak-site-branded name, May 2020 onward); Wizard Spider (CrowdStrike's intrusion-set naming for the operator cohort, predating the Conti brand and continuing through Conti-successor-brand era); UNC1878 (Mandiant's earlier intrusion-set naming for the same cohort, partially superseded by the operator-cohort-rebranding pattern post-2022); TrickBot Group (informal industry naming linking the cohort to its earlier banker-trojan operating substrate); external cyber-threat-intel taxonomy ID S0575. Conti is operationally the successor brand to Ryuk (2018–2020) within the same operator-cohort identity, and predecessor brand-of-record to the post-May-2022 dispersal cohort (Black Basta, Royal / BlackSuit, Karakurt, BlackByte, Quantum / Zeon, AvosLocker partial overlap, and broader Conti-diaspora affiliate placements).
Active
sunset (2022-05) — operator-cluster dissolution announced internally during May 2022 following the late-February-2022 ContiLeaks insider-disclosure event in which a pro-Ukraine cluster member published approximately 60,000 internal chat-log messages, source code, and operational documents in retaliation for the operator's public alignment with the Russian state's invasion of Ukraine. The Conti-branded leak site went offline in late May / early June 2022; the operator cohort dispersed into multiple successor brands while retaining operator continuity at the personnel level. No genuine Conti-branded operations have been observed post-mid-2022; the brand is fully sunset, but operator continuity into the successor brands is the dominant 2022–2025 ransomware-sector trajectory.
First observed
2020-05 (Conti leak-site debut May 2020; Wizard-Spider-cohort ransomware operations under earlier branding, principally Ryuk, dated to August 2018).
Used by Groups
defunct-operator (no current OAK-G entry). The historical Conti / Wizard Spider operator cohort is the lineage progenitor of multiple current G05-class ransomware operators (see Discussion). Conti's operating cohort is documented in the CISA AA21-265A, CISA AA22-046A, and successor advisories; OFAC-attribution at the cohort level is via the broader Russian-cybercrime-ecosystem designation surface (Evil Corp 2019 designation as the cohort-adjacent reference point, plus the post-Conti TrickBot-Group designations and the OAK-G06 Evil Corp / OAK-G05 LockBit connections that document operator-mobility within the Russian-speaking-RaaS-cohort umbrella). For OAK Software-entry purposes the appropriate framing is defunct-brand, operator-cohort-survives-as-multiple-Group-entries.
Host platforms
Windows (primary, all variants); Linux (a Conti-Linux variant emerged in late 2021 with VMware ESXi targeting, mirroring the broader RaaS-sector ESXi pivot; partial code reuse of the Conti-Linux variant is documented in Hive's Linux build per Mandiant); the Conti v3 Windows codebase was leaked in full during the ContiLeaks dump and has since been forked / rebadged by multiple unrelated groups (LockBit Green is the highest-profile rebadge — see OAK-S23 — but unaffiliated commodity-tier Conti-fork builds also circulate).
Observed Techniques
OAK-T7.001 (mixer-routed-hop, the dominant Conti-affiliate ransom-laundering route 2020–2022 with the principal venue being the Russian-speaking-mixer ecosystem; ChipMixer pre-takedown was a documented routing point per Chainalysis); OAK-T7.002 (CEX deposit-address layering, with Garantex specifically named as a Conti-laundering venue in the April 2022 OFAC designation press release — [ofac2022garantex] — citing approximately $6M in Conti-attributable flows through Garantex as part of the basis for the designation, which is the cleanest single-document upstream-G05-class-ransomware × downstream-G03 attribution chain in the OAK citation base); OAK-T8.001 (common-funder cluster reuse, the load-bearing Technique for tracking operator continuity across the Conti-to-successor-brand dispersal — the wallet-cluster persistence is what allowed Mandiant, Chainalysis, and the U.S. government to identify Black Basta, Royal, Karakurt, and BlackByte as Conti-cohort-continuations in the months after the May 2022 dissolution).

Description

Conti is the now-defunct ransomware operator brand maintained by the Russian-speaking Wizard Spider / TrickBot Group operator cohort from approximately May 2020 through May 2022, succeeding the cohort's earlier Ryuk brand (August 2018 – mid-2020) and preceding the post-dissolution successor-brand dispersal (Black Basta, Royal / BlackSuit, Karakurt, BlackByte, Quantum / Zeon, and partial overlaps with AvosLocker). Conti was, alongside REvil and LockBit, one of the three dominant RaaS strains of 2020–2022 by attributable victim count and ransom-payment volume; CISA AA22-046A documented over 1,000 victim organisations through early 2022 and Chainalysis tracking placed Conti's 2021 ransom-payment volume at approximately $180M, the largest of any single strain that year. The operator cohort is a Russian-speaking criminal cohort with continuity to the TrickBot banker-trojan operation (active from approximately 2016) and to the Ryuk ransomware operation (2018–2020); the same operator persona set runs across all three brands at the cluster level, with periodic affiliate-side reorganisations.

The encryptor's distinguishing technical features include multi-threaded fast-encryption mode (selectable per-deployment), aggressive lateral-movement-and-self-spreading via SMB share enumeration (a defining Conti-affiliate-deployment fingerprint), the Conti-Linux variant for VMware ESXi targeting (mirroring the broader sector pivot to hypervisor-level deployments), and an unusually well-developed double-extortion infrastructure (the Conti News leak site, a sophisticated negotiation-portal, and a published affiliate handbook recovered during ContiLeaks). The affiliate-program structure was a textbook RaaS split with an approximately 20–30% operator cut; the operator-side included a documented internal hierarchy with developers, system administrators, HR, OSINT analysts, and even physical-office infrastructure in St. Petersburg per the ContiLeaks recovered chats, an organisational sophistication that exceeded any contemporary RaaS brand on the public record.

The family's role in the historical Russian-cybercrime-ecosystem monetization chain was the encryption-and-extortion node feeding Russian-speaking-cluster laundering venues — Garantex (OAK-G03) explicitly per the April 2022 OFAC designation that named Conti-attributable proceeds among the basis-for-designation evidence, plus the broader Russian-speaking-mixer ecosystem (ChipMixer pre-takedown, Sinbad pre-takedown). The ContiLeaks insider-disclosure event of late February 2022 — triggered by the operator's public statement aligning with the Russian state's invasion of Ukraine — produced an unprecedented public record of Conti's internal operating reality (recovered chats, source code, operator persona inventory, affiliate roster fragments, victim-negotiation logs), which became the canonical primary-source corpus for academic and industry analysis of how a major RaaS brand actually operates internally. The combination of that public record and the operator's brand-association with Russian-state-aligned politics catalysed the May 2022 cohort dissolution into the successor-brand network described in the Discussion section below.

Observed examples

  • Costa Rica government attack (April 2022, ~$10M ransom demand). Conti deployment against multiple Costa Rican government ministries (Ministry of Finance, Ministry of Science Innovation Technology and Telecommunications, Costa Rican Social Security Fund, multiple municipal authorities) starting April 12, 2022; the attack triggered Costa Rica's national-emergency declaration on May 8, 2022 (the first time any nation declared a national emergency in response to a cyberattack); Conti demanded $10M in Bitcoin (later raised to $20M); the Costa Rican government refused to pay; the U.S. Department of State announced a $10M reward for information leading to apprehension of Conti leaders the following day. The attack is the canonical case of ransomware deployment against a sovereign nation's core government infrastructure as political-pressure operation and is widely read as the operationally-final Conti-branded campaign before the cohort dissolution; it is also the highest-profile case in the public record of an apparent intentional-bridge-burn by an operator already preparing internal dissolution. Confirmed-grade attribution per multi-government public statements and per CrowdStrike, Mandiant, and Recorded Future post-incident analysis.
  • Ireland Health Service Executive (HSE) attack (May 2021, ~$600M+ remediation cost). Conti deployment against Ireland's national public-healthcare system disrupted hospital operations across Ireland for weeks; the HSE refused ransom payment; the Conti operators eventually published a free decryptor (the recovery of which Mandiant's analysis treats as evidence of operator-internal political-risk-management rather than altruism). PwC's post-incident report estimated direct and indirect remediation cost at over €600M. Confirmed-grade.
  • JBS Foods (May 2021, $11M ransom paid). Conti-affiliate deployment against JBS USA's meat-processing infrastructure; ransom of approximately $11M in Bitcoin paid; one of the highest-profile food-supply-chain ransomware events of the 2021 cohort. (Some early reporting attributed JBS to REvil rather than Conti; the public record is partially contested but the Conti-cohort attribution is the dominant industry reading per Recorded Future and Chainalysis tracking.)
  • CISA AA22-046A campaign cohort (through early 2022). The advisory documents over 1,000 named-and-unnamed Conti victims across U.S. critical-infrastructure sectors (healthcare, manufacturing, financial-services, energy, government); confirmed-grade aggregate.
  • OFAC Garantex designation evidence base (April 5, 2022). OFAC press release JY0701 ([ofac2022garantex]) explicitly named Conti-attributable proceeds among the >$100M illicit-linked transaction evidence supporting the Garantex designation, citing approximately $6M of Conti ransomware proceeds laundered through Garantex. Confirmed-grade upstream-Conti × downstream-Garantex chain anchor.
  • OAK on-chain example surface. The Garantex-Conti chain documented in [ofac2022garantex] is the strongest candidate for a future OAK examples/ entry showing the OAK-S26-binary × OAK-G03-Garantex × T7.002 worked example, even though OAK-S26's operator cluster has no current OAK-G entry.

Detection / attribution signals

Defenders should treat Conti as a historical-anchor entry rather than an active-detection target, with the on-chain forensic signal continuing to be relevant for tracking operator continuity into the successor brands:

  • Host-layer process-tree fingerprints (historical, but applicable to forked builds) — the Conti v3 source code is publicly available post-ContiLeaks and has been forked by multiple unrelated groups; characteristic file-extension changes (.conti); ransom-note filenames (R3ADM3.txt, readme.txt); the multi-threaded fast-encryption-mode signature; aggressive SMB-share self-spreading; vssadmin / wmic shadow-copy-deletion sequences.
  • Pre-encryption tradecraft (Wizard-Spider-cohort canonical) — initial access via TrickBot / BazarLoader / IcedID phishing chains (the Wizard Spider cohort's banker-trojan operating substrate fed Conti-affiliate intrusions through 2021–2022); Cobalt Strike post-exploitation deployment; Mimikatz / domain-admin credential theft; AnyDesk / Atera / Splashtop persistence-and-remote-access tooling installation.
  • On-chain-layer signatures (the OAK-relevant signal, applicable to operator-cohort-continuity tracking) — wallet-cluster persistence (OAK-T8.001) across the Ryuk → Conti → successor-brand dispersal is the principal signature used by Chainalysis, TRM Labs, Mandiant, and the U.S. government to identify Black Basta, Royal / BlackSuit, Karakurt, and BlackByte as Conti-cohort-continuations; the April 2022 OFAC Garantex designation's $6M-Conti-attributable evidence is the single highest-confidence on-chain attribution document for the Conti-to-Garantex chain specifically.
  • CTI vendor coverage (historical and continuing for successor-brand tracking) — CrowdStrike (Wizard Spider naming and continuous tracking through successor brands), Mandiant (UNC1878 historical naming, plus successor-brand-attribution work), Microsoft Threat Intelligence (DEV-0237 and successor-cohort tracking), Recorded Future (sustained Conti-and-successor-brand reporting), Sophos (the Conti-and-successor "State of Ransomware" thread), Trend Micro (continuous version-and-fork analysis), Chainalysis and TRM Labs (on-chain operator-cohort-continuity tracking).
  • Primary-source corpus (ContiLeaks) — the late-February-2022 ContiLeaks insider-disclosure remains the most-extensive publicly-available primary-source corpus on any major RaaS operator-cohort and is the canonical reference for academic and industry analysis of Conti's internal organisational structure; defenders writing operator-cohort tracking should treat the ContiLeaks corpus and Recorded Future / Mandiant secondary analysis of it as the principal evidence base.

Note: omit specific file hashes from this entry. The Conti v3 source code is publicly available post-ContiLeaks, so Conti-fork build hashes are not the appropriate detection variable; behavioural patterns and operator-cohort wallet-cluster persistence are.

Citations

  • [cisaaa22046a] — CISA / FBI / Secret Service joint advisory AA22-046A on Conti ransomware. (NEW citation — see summary.)
  • [cisaaa21265a] — CISA / FBI joint advisory AA21-265A, the earlier 2021 Conti advisory. (NEW citation — see summary.)
  • [ofac2022garantex] — Treasury OFAC Garantex designation press release JY0701, April 5, 2022; explicitly cites Conti-attributable proceeds among the basis-for-designation evidence. (Already present in citations.bib per OAK-G03.)
  • [contileaks2022] — ContiLeaks insider-disclosure corpus, late February 2022; recovered by Twitter user @ContiLeaks (a pro-Ukraine cluster member) and subsequently archived by VX-Underground and others. (NEW citation — see summary.)
  • [mandiantcontileaks2022] — Mandiant analysis of the ContiLeaks corpus and Conti's organisational structure. (NEW citation — see summary.)
  • [chainalysis2022conti] — Chainalysis Conti-attributable ransom-payment-volume tracking and the Conti-to-Garantex chain analysis. (NEW citation — see summary.)
  • [crowdstrikewizardspider2022] — CrowdStrike Wizard Spider operator-cohort tracking through the Conti dissolution and successor-brand dispersal. (NEW citation — see summary.)
  • [recordedfuturecontihse2021] — Recorded Future / Insikt Group analysis of the Ireland HSE attack. (NEW citation — see summary.)
  • [costaricaconti2022] — Costa Rica national-emergency declaration and Conti-attribution coverage; combined U.S. State Department $10M reward announcement. (NEW citation — see summary.)
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; cross-family context for the Conti-successor-brand-dispersal volume distribution.

Discussion

On lineage as the central framing. OAK-S26's principal value as a Software entry is not as an active-detection target — Conti is sunset, and active-detection-relevance for the v3 source code belongs to the unaffiliated forks rather than to any single operator-cohort. The principal value is as the lineage progenitor of multiple current G05-class operators. The Conti operator cohort's May 2022 dissolution is the canonical worked example of RaaS operator-cohort dispersal-into-successor-brands as a continuity-management response to brand-toxicity (here, brand-toxicity from the operator's politically-motivated alignment with the Russian state's Ukraine invasion combined with the ContiLeaks insider-disclosure event). The successor-brand dispersal is documented in the public record across:

  • Black Basta (April 2022 emergence, immediately pre-Conti-dissolution) — Mandiant and Microsoft attribute Black Basta to Conti-cohort continuity at the operator-personnel level; affiliate continuity to the Conti affiliate roster is documented; Black Basta is the principal direct-successor brand by attributable victim count through 2024–2025 and is itself the subject of major U.S. government advisories.
  • Royal / BlackSuit (September 2022 emergence as Royal; rebrand to BlackSuit in mid-2023) — Conti-cohort operator continuity attributed by Mandiant, Microsoft, CISA AA23-061A; healthcare-sector targeting profile inherited from the Conti operating model.
  • Karakurt (mid-2021 emergence as a Conti-side-channel data-extortion-only group, surviving the brand dissolution) — Conti-cohort-continuity confirmed by CISA AA22-152A.
  • BlackByte (2021 emergence with Conti-cohort partial overlap; 2022–2025 continued operations).
  • Quantum / Zeon (2022 short-lived) — direct Conti-cohort continuity per CrowdStrike.
  • AvosLocker (partial operator-overlap rather than full Conti-cohort-continuity).

The aggregate signal is that the Conti operator cohort survives as the largest single source of current Russian-speaking-RaaS operator personnel, distributed across the successor brands rather than concentrated in any one brand. This dispersal pattern is structurally distinct from the LockBit-style brand-continuity-under-versioned-encryptor-rotation pattern (OAK-S23) and from the ALPHV-style self-exit-scam-into-affiliate-diaspora pattern (OAK-S24); it is the canonical insider-disclosure-and-political-toxicity-driven-cohort-dispersal pattern for the sector.

On predecessors. Conti's direct predecessor at the operator-cohort level is Ryuk ransomware (2018–2020), which the same Wizard Spider / TrickBot Group cohort operated before launching the Conti brand. Ryuk itself is partially derived from Hermes ransomware (a 2017 Korean-origin family that the cohort licensed or forked); the Ryuk-to-Conti transition is widely read as a brand-rotation rather than a substantive operational change. The earlier Wizard Spider cohort substrate is the TrickBot banker-trojan operation (2016 onward), which provided the initial-access-and-credential-theft tooling that fed Conti-affiliate intrusions through the brand's full lifetime.

On market-share evolution. Conti was the dominant RaaS strain by attributable ransom-payment volume in 2021 (~$180M per Chainalysis) and one of the top three by attributable victim count across 2020–2022. The post-dissolution successor-brand cohort, taken in aggregate, retained or grew that market share through 2023–2025; mapping per-successor-brand volumes is non-trivial because of the cohort-continuity-but-brand-rotation pattern, but Black Basta alone has registered as a top-three-by-volume strain in multiple Chainalysis annual reports post-2022.

On takedown / disruption history. Conti was not sunset by a government takedown — the cohort was disrupted by an insider-disclosure event (ContiLeaks, late February 2022) catalysed by the operator's politically-motivated public alignment with the Russian state's Ukraine invasion. This dissolution mechanism is structurally distinct from LockBit (Operation Cronos, government takedown) and ALPHV (operator self-exit-scam), and it is the only major RaaS-brand sunset on the public record driven primarily by operator-internal political dissent. The U.S. State Department's $10M reward announcement (May 2022, in response to the Costa Rica attack) added external pressure but post-dated the internal-disclosure-driven dissolution decision per the ContiLeaks corpus and Mandiant secondary analysis.

On the OAK Software-vs-Group split for a defunct operator. OAK-S26 (this entry) is the Conti encryptor codebase and historical brand. There is no current OAK-G entry for the Conti / Wizard Spider operator cohort because the cohort no longer operates under that brand identity; the appropriate Group-side modelling is the successor-brand network (Black Basta, Royal / BlackSuit, Karakurt, BlackByte), each of which would warrant a separate OAK-G entry as the v0.x Group catalog expands. The OAK-G06 Evil Corp entry already documents one Russian-speaking-RaaS-cohort operator-mobility pattern; future Conti-successor-brand OAK-G entries (OAK-G11+ in the eventual v0.x Group expansion) will document the parallel Conti-cohort-mobility pattern and reference OAK-S26 as the historical-anchor Software entry. Conti is, in this v0.1 entry's framing, the historical anchor of the lineage that continues as multiple current Group-level threats rather than a single Group-level threat in its own right.

Techniques observed (3)

Used by