CARDS
CARDS
Conti is a Russia-based ransomware-as-a-service (RaaS) operation that first emerged in December 2019 under the alias Wizard Spider, a group also known for the TrickBot banking trojan. This financially motivated threat actor quickly evolved from an initial malware strain into a highly prolific RaaS model, distinguishing itself through its rapid, multi-threaded encryption capabilities that made it faster than many contemporary ransomware variants. Conti was an early and prominent adopter of the double extortion tactic, involving both data encryption and exfiltration with threats of public release. The group's operational structure, while affiliate-based, sometimes varied from typical RaaS models by reportedly paying deployers a fixed wage rather than a commission. A critical turning point for Conti was its public declaration of support for Russia following the invasion of Ukraine in February 2022, which led to significant internal data leaks (ContiLeaks) and ultimately its official disbandment in May 2022, although many former members are believed to have transitioned to other ransomware operations.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Aliases1
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Associated Activity1
ATT&CK IDs1
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| conti Ransomware / Extortion Operations4 | conti Ransomware / Extortion Operations is retained in the campaign database for conti. Conti is an extremely damaging ransomware due to the speed with which it encrypts data and spreads to other systems. It was first observed in 2020 and it is thought to be led by a Russia-based cybercrime group that goes under the Wizard Spider pseudonym. In early May 2022, the US government announced a reward of up to $10 million for information on the Conti ransomware gang. |
Indicators
SOCRadar reports 7631 IOCs for this profile. IntelliOS currently retains 47 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 2 source groups tracked; 1 currently contributes retained observable or context rows.
Retained Observables
Showing 47 of 47
| Type | Value | Source |
|---|---|---|
| Network Indicator | badiwaw[.]com3 | CISA Alert |
| Network Indicator | balacif[.]com3 | CISA Alert |
| Network Indicator | barovur[.]com3 | CISA Alert |
| Network Indicator | basisem[.]com3 | CISA Alert |
| Network Indicator | bimafu[.]com3 | CISA Alert |
| Network Indicator | bujoke[.]com3 | CISA Alert |
| Network Indicator | buloxo[.]com3 | CISA Alert |
| Network Indicator | bumoyez[.]com3 | CISA Alert |
| Network Indicator | bupula[.]com3 | CISA Alert |
| Network Indicator | cajeti[.]com3 | CISA Alert |
| Network Indicator | cilomum[.]com3 | CISA Alert |
| Network Indicator | codasal[.]com3 | CISA Alert |
| Network Indicator | comecal[.]com3 | CISA Alert |
| Network Indicator | dawasab[.]com3 | CISA Alert |
| Network Indicator | derotin[.]com3 | CISA Alert |
| Network Indicator | dihata[.]com3 | CISA Alert |
| Network Indicator | dirupun[.]com3 | CISA Alert |
| Network Indicator | dohigu[.]com3 | CISA Alert |
| Network Indicator | dubacaj[.]com3 | CISA Alert |
| Network Indicator | fecotis[.]com3 | CISA Alert |
| Network Indicator | fipoleb[.]com3 | CISA Alert |
| Network Indicator | fofudir[.]com3 | CISA Alert |
| Network Indicator | fulujam[.]com3 | CISA Alert |
| Network Indicator | ganobaz[.]com3 | CISA Alert |
| Network Indicator | gerepa[.]com3 | CISA Alert |
| Network Indicator | gucunug[.]com3 | CISA Alert |
| Network Indicator | guvafe[.]com3 | CISA Alert |
| Network Indicator | hakakor[.]com3 | CISA Alert |
| Network Indicator | hejalij[.]com3 | CISA Alert |
| Network Indicator | hepide[.]com3 | CISA Alert |
| Network Indicator | hesovaw[.]com3 | CISA Alert |
| Network Indicator | hewecas[.]com3 | CISA Alert |
| Network Indicator | hidusi[.]com3 | CISA Alert |
| Network Indicator | hireja[.]com3 | CISA Alert |
| Network Indicator | hoguyum[.]com3 | CISA Alert |
| Network Indicator | jecubat[.]com3 | CISA Alert |
| Network Indicator | jegufe[.]com3 | CISA Alert |
| Network Indicator | joxinu[.]com3 | CISA Alert |
| Network Indicator | kelowuh[.]com3 | CISA Alert |
| Network Indicator | kidukes[.]com3 | CISA Alert |
| Network Indicator | kipitep[.]com3 | CISA Alert |
| Network Indicator | kirute[.]com3 | CISA Alert |
| Network Indicator | kogasiv[.]com3 | CISA Alert |
| Network Indicator | kozoheh[.]com3 | CISA Alert |
| Network Indicator | kuxizi[.]com3 | CISA Alert |
| Network Indicator | kuyeguh[.]com3 | CISA Alert |
| Network Indicator | lipozi[.]com3 | CISA Alert |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Conti | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Conti | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/conti | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | CISA Alert: Conti Ransomware https://www.cisa.gov/news-events/alerts/2021/09/22/conti-ransomware | IOC Source |
| 4 | conti - Ransomware.live group profile https://www.ransomware.live/group/conti | Ransomware.live campaign row source for conti Ransomware / Extortion Operations. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Conti, then compares naming and aliases against SOCRadar Actor Alias Index where collision checks exist.
The retained collision rows point to possible boundary questions involving conti / WIZARD SPIDER; conti / GRIM SPIDER; conti / UNC1878 / WIZARD SPIDER based on shared evidence such as Wizard Spider; Gold Ulrick; UNC1878. These notes preserve reader context; IntelliOS does not automatically merge actor records.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| SOCRadar Actor Alias Index possible same actor | conti / WIZARD SPIDER | Wizard Spider | Retain as a source-boundary note; do not merge automatically. |
| SOCRadar Actor Alias Index possible same actor | conti / GRIM SPIDER | Gold Ulrick | Retain as a source-boundary note; do not merge automatically. |
| SOCRadar Actor Alias Index possible same actor | conti / UNC1878 / WIZARD SPIDER | UNC1878 | Retain as a source-boundary note; do not merge automatically. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |