logo

From the Labs: YARA Rule for Detecting Conti

ID: b0fdaa0e-f1d8-5a21-8bb6-a3a1f95911a3

STIX ID: report--b0fdaa0e-f1d8-5a21-8bb6-a3a1f95911a3

Feed Name: ReversingLabs Blog

Threat Score
78/100

Date Published: 2025-05-13

Date Updated: 2026-04-29

Author: Paul Roberts

...
...

This report profiles the Conti ransomware-as-a-service operation, outlining its prevalence, double-extortion extortion methodology, common initial access vectors (spear-phishing, stolen/weak RDP credentials), post-compromise tooling (Mimikatz, TrickBot, Cobalt Strike), and intrusion behaviors; it also provides a ReversingLabs YARA rule and guidance for detecting Conti in customer environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.