logo

Despite Leaks, Conti Ransomware Attacks Persist

ID: 6fd7be7d-8c75-592e-b629-dc2ed8644c2c

STIX ID: report--6fd7be7d-8c75-592e-b629-dc2ed8644c2c

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

ThreatLabz details a January 2022 update to the Conti ransomware family that adds Safe Mode-based encryption (via -safeboot, -user, -pass), automatic Safe Mode login through registry manipulation, network-enabled Safe Mode to reach shares, per-file ChaCha symmetric keys protected by a hardcoded 4096-bit RSA public key, API hashing change (Murmur3) for evasion, randomized mixed-case encrypted file extensions, a wallpaper payload, and a streamlined victim portal; the report includes SHA256 IoCs and Zscaler detection names.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.