logo

An insider insights into Conti operations

ID: 98a80d07-00e6-5bd7-ae1c-cefbb0c8e048

STIX ID: report--98a80d07-00e6-5bd7-ae1c-cefbb0c8e048

Feed Name: Sekoia.com

Threat Score
80/100

Date Published: 2021-08-17

Date Updated: 2026-07-20

...
...

This report analyzes leaked Conti ransomware training materials and forum activity, detailing the group's evolution from TrickBot/Ryuk operators into a highly organized ransomware cartel that uses double-extortion, fast multi-threaded encryption, loaders like BazarLoader, and known exploits (EternalBlue, Zerologon, PrintNightmare). It describes internal structure and recruitment, opsec advice found in the leaks, and concludes the material provides useful intelligence and detection opportunities despite containing no novel techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.