RU

Conti

High ConfidenceHigh Threat

Wizard Spider • UNC1878 • GOLD ULRICK

Conti was one of the most prolific ransomware-as-a-service operations, active from 2020 until its dissolution in 2022. The group was responsible for hundreds of attacks against healthcare, government, and critical infrastructure organizations worldwide. Conti's internal communications were leaked in February 2022 following their public support for Russia's invasion of Ukraine, revealing their organizational structure and ties to the Russian cybercriminal ecosystem. Despite officially disbanding, Conti members have dispersed to other ransomware operations including Royal, Black Basta, and others.

Origin: Russia
Sponsor: Cybercriminal (No State Sponsor)
Active: 2020 - Present
Victims: 1000+ organizations
Advanced
Active
Financial Gain
Risk Assessment
81
Composite Risk Score
High Risk
ARCS Compliance85
Escalation Risk82
Grievance Index70
Infrastructure Impact88
History & Evolution

Conti was one of the most prolific ransomware-as-a-service operations, active from 2020 until its dissolution in 2022. The group was responsible for hundreds of attacks against healthcare, government, and critical infrastructure organizations worldwide. Conti's internal communications were leaked in February 2022 following their public support for Russia's invasion of Ukraine, revealing their organizational structure and ties to the Russian cybercriminal ecosystem. Despite officially disbanding, Conti members have dispersed to other ransomware operations including Royal, Black Basta, and others.

Targeting

Target Sectors

HealthcareGovernmentManufacturingEducation

Target Regions

GlobalUnited StatesEurope
Attribution & Affiliations

Attributed to Cybercriminal (No State Sponsor) (Russia). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Moderately
Targeting
Moderately
Adaptability
High
Persistence
Disbanded
Op Tempo
Disbanded (Members Active)
Status

Future Outlook

Conti is expected to continue operations targeting Healthcare sectors.

Timeline of Key Events
2020
Major

First observed activity of Conti

2024
Moderate

Continued active operations