An insider insights into Conti operations
ID: 98a80d07-00e6-5bd7-ae1c-cefbb0c8e048
STIX ID: report--98a80d07-00e6-5bd7-ae1c-cefbb0c8e048
Feed Name: Sekoia.com
This report analyzes leaked Conti ransomware training materials and forum activity, detailing the group's evolution from TrickBot/Ryuk operators into a highly organized ransomware cartel that uses double-extortion, fast multi-threaded encryption, loaders like BazarLoader, and known exploits (EternalBlue, Zerologon, PrintNightmare). It describes internal structure and recruitment, opsec advice found in the leaks, and concludes the material provides useful intelligence and detection opportunities despite containing no novel techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
