01
Conti is tracked as an affiliate-enabled ransomware service.1
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
CARDS
Conti is a Russia-based ransomware-as-a-service (RaaS) operation that first emerged in December 2019 under the alias Wizard Spider, a group also known for the TrickBot banking trojan. This financially motivated threat actor quickly evolved from an initial malware strain into a highly prolific RaaS model, distinguishing itself through its rapid, multi-threaded encryption capabilities that made it faster than many contemporary ransomware variants. Conti was an early and prominent adopter of the double extortion tactic, involving both data encryption and exfiltration with threats of public release. The group's operational structure, while affiliate-based, sometimes varied from typical RaaS models by reportedly paying deployers a fixed wage rather than a commission. A critical turning point for Conti was its public declaration of support for Russia following the invasion of Ukraine in February 2022, which led to significant internal data leaks (ContiLeaks) and ultimately its official disbandment in May 2022, although many former members are believed to have transitioned to other ransomware operations.
Directory Briefing
01
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
02
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
03
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
04
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
05
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
06
Reported tooling or behavior includes PowerShell, remote execution, or other dual-use administration behavior; detection must distinguish authorized administration from anomalous context and sequence.
07
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
08
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
09
Retained targeting includes Construction of Buildings, Food Manufacturing, Rail Transportation, Software Publishers, and Real Estate across Andorra, United Arab Emirates, Albania, and Armenia; translate those sectors into the organization's exposed systems and high-value data.
10
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Bottom Line Up Front
The brand supplies shared capabilities, but affiliates can change access methods and tooling; incident scoping should follow observed behavior rather than assume one fixed playbook.
The retained behavior points to credentials, remote access, phishing, or exposed services; preserve authentication, VPN, edge-device, email, and remote-administration evidence together.
Check for earlier credential use, remote sessions, administrative changes, and data access because public actor records often understate the full pre-impact timeline.
Evidence includes credential or account abuse; response should cover privileged, service, remote-access, SaaS, and recovery identities—not just interactive user passwords.
Lateral movement, administrative access, and shared server infrastructure can turn a limited foothold into broad business interruption.
Reported tooling or behavior includes PowerShell, remote execution, or other dual-use administration behavior; detection must distinguish authorized administration from anomalous context and sequence.
Defense impairment or evidence removal is retained in the source record. Protect immutable backups and investigate access to recovery systems before trusting them.
Collection or exfiltration behavior includes data staging and exfiltration; counsel and forensics need a shared record of what was accessed, staged, and transferred.
Retained targeting includes Construction of Buildings, Food Manufacturing, Rail Transportation, Software Publishers, and Real Estate across Andorra, United Arab Emirates, Albania, and Armenia; translate those sectors into the organization's exposed systems and high-value data.
Align counsel, forensics, identity, recovery, insurance, communications, and regulatory analysis around one compromise timeline and one evidence-preservation plan.
Decision Context
Conti is a Russia-based ransomware-as-a-service (RaaS) operation that first emerged in December 2019 under the alias Wizard Spider, a group also known for the TrickBot banking trojan. This financially motivated threat actor quickly evolved from an initial malware strain into a highly prolific RaaS model, distinguishing itself through its rapid, multi-threaded encryption capabilities that made it faster than many contemporary ransomware variants. Conti was an early and prominent adopter of the double extortion tactic, involving both data encryption and exfiltration with threats of public release. The group's operational structure, while affiliate-based, sometimes varied from typical RaaS models by reportedly paying deployers a fixed wage rather than a commission. A critical turning point for Conti was its public declaration of support for Russia following the invasion of Ukraine in February 2022, which led to significant internal data leaks (ContiLeaks) and ultimately its official disbandment in May 2022, although many former members are believed to have transitioned to other ransomware operations.1,2
Actor Card Detail
Victimology
No named victim organizations are retained in the cited source artifacts for this profile. Countries and sectors are targeting context, not victim identities.
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure1,2
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| conti Ransomware / Extortion Operations4 | conti Ransomware / Extortion Operations is retained in the campaign database for conti. Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang. |
Indicators
SOCRadar reports 7631 IOCs for this profile. IntelliOS currently retains 47 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 2 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 47 of 47
| Type | Value | Source |
|---|---|---|
| Network Indicator | badiwaw[.]com3 | CISA Alert |
| Network Indicator | balacif[.]com3 | CISA Alert |
| Network Indicator | barovur[.]com3 | CISA Alert |
| Network Indicator | basisem[.]com3 | CISA Alert |
| Network Indicator | bimafu[.]com3 | CISA Alert |
| Network Indicator | bujoke[.]com3 | CISA Alert |
| Network Indicator | buloxo[.]com3 | CISA Alert |
| Network Indicator | bumoyez[.]com3 | CISA Alert |
| Network Indicator | bupula[.]com3 | CISA Alert |
| Network Indicator | cajeti[.]com3 | CISA Alert |
| Network Indicator | cilomum[.]com3 | CISA Alert |
| Network Indicator | codasal[.]com3 | CISA Alert |
| Network Indicator | comecal[.]com3 | CISA Alert |
| Network Indicator | dawasab[.]com3 | CISA Alert |
| Network Indicator | derotin[.]com3 | CISA Alert |
| Network Indicator | dihata[.]com3 | CISA Alert |
| Network Indicator | dirupun[.]com3 | CISA Alert |
| Network Indicator | dohigu[.]com3 | CISA Alert |
| Network Indicator | dubacaj[.]com3 | CISA Alert |
| Network Indicator | fecotis[.]com3 | CISA Alert |
| Network Indicator | fipoleb[.]com3 | CISA Alert |
| Network Indicator | fofudir[.]com3 | CISA Alert |
| Network Indicator | fulujam[.]com3 | CISA Alert |
| Network Indicator | ganobaz[.]com3 | CISA Alert |
| Network Indicator | gerepa[.]com3 | CISA Alert |
| Network Indicator | gucunug[.]com3 | CISA Alert |
| Network Indicator | guvafe[.]com3 | CISA Alert |
| Network Indicator | hakakor[.]com3 | CISA Alert |
| Network Indicator | hejalij[.]com3 | CISA Alert |
| Network Indicator | hepide[.]com3 | CISA Alert |
| Network Indicator | hesovaw[.]com3 | CISA Alert |
| Network Indicator | hewecas[.]com3 | CISA Alert |
| Network Indicator | hidusi[.]com3 | CISA Alert |
| Network Indicator | hireja[.]com3 | CISA Alert |
| Network Indicator | hoguyum[.]com3 | CISA Alert |
| Network Indicator | jecubat[.]com3 | CISA Alert |
| Network Indicator | jegufe[.]com3 | CISA Alert |
| Network Indicator | joxinu[.]com3 | CISA Alert |
| Network Indicator | kelowuh[.]com3 | CISA Alert |
| Network Indicator | kidukes[.]com3 | CISA Alert |
| Network Indicator | kipitep[.]com3 | CISA Alert |
| Network Indicator | kirute[.]com3 | CISA Alert |
| Network Indicator | kogasiv[.]com3 | CISA Alert |
| Network Indicator | kozoheh[.]com3 | CISA Alert |
| Network Indicator | kuxizi[.]com3 | CISA Alert |
| Network Indicator | kuyeguh[.]com3 | CISA Alert |
| Network Indicator | lipozi[.]com3 | CISA Alert |
Actor Chronology
No source-backed actor-activity dates are currently retained. Publication and record-maintenance dates are not promoted into activity dates.
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Conti | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Conti | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Conti, then compares naming and aliases against SOCRadar Actor Alias Index where collision checks exist.
The retained collision rows point to possible boundary questions involving conti / WIZARD SPIDER; conti / GRIM SPIDER; conti / UNC1878 / WIZARD SPIDER based on shared evidence such as Wizard Spider; Gold Ulrick; UNC1878. These notes preserve reader context; IntelliOS does not automatically merge actor records.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| SOCRadar Actor Alias Index possible same actor | conti / WIZARD SPIDER | Wizard Spider | Retain as a source-boundary note; do not merge automatically. |
| SOCRadar Actor Alias Index possible same actor | conti / GRIM SPIDER | Gold Ulrick | Retain as a source-boundary note; do not merge automatically. |
| SOCRadar Actor Alias Index possible same actor | conti / UNC1878 / WIZARD SPIDER | UNC1878 | Retain as a source-boundary note; do not merge automatically. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Threat actor directory source for profile fields and reported activity. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/conti | Actor-specific source for ransomware profile metadata and reported IOC counts when available. |
| 3 | CISA Alert: Conti Ransomware https://www.cisa.gov/news-events/alerts/2021/09/22/conti-ransomware | IOC Source |
| 4 | conti - Ransomware.live group profile https://www.ransomware.live/group/conti | Ransomware.live campaign row source for conti Ransomware / Extortion Operations. |