From the Labs: YARA Rule for Detecting Conti
ID: b0fdaa0e-f1d8-5a21-8bb6-a3a1f95911a3
STIX ID: report--b0fdaa0e-f1d8-5a21-8bb6-a3a1f95911a3
Feed Name: ReversingLabs Blog
Threat Score
This report profiles the Conti ransomware-as-a-service operation, outlining its prevalence, double-extortion extortion methodology, common initial access vectors (spear-phishing, stolen/weak RDP credentials), post-compromise tooling (Mimikatz, TrickBot, Cobalt Strike), and intrusion behaviors; it also provides a ReversingLabs YARA rule and guidance for detecting Conti in customer environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
