Conti

S0575

Malware.View on attack.mitre.org

About this malware

Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1016
System Network Configuration Discovery

Conti can retrieve the ARP cache from the local system by using the GetIpNetTable() API call and check to ensure IP addresses it connects to are for local, non-Internet, systems.

T1018
Remote System Discovery

Conti has the ability to discover hosts on a target network.

T1021.002
SMB/Windows Admin Shares

Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network.

T1027
Obfuscated Files or Information

Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls.

T1049
System Network Connections Discovery

Conti can enumerate routine network connections from a compromised host.

T1055.001
Dynamic-link Library Injection

Conti has loaded an encrypted DLL into memory and then executes it.

T1057
Process Discovery

Conti can enumerate through all open processes to search for any that have the string “sql” in their process name.

T1059.003
Windows Command Shell

Conti can utilize command line options to allow an attacker control over how it scans and encrypts files.

T1080
Taint Shared Content

Conti can spread itself by infecting other remote machines via network shared drives.

T1083
File and Directory Discovery

Conti can discover files on a local system.

T1106
Native API

Conti has used API calls during execution.

T1135
Network Share Discovery

Conti can enumerate remote open SMB network shares using NetShareEnum().

T1140
Deobfuscate/Decode Files or Information

Conti has decrypted its payload using a hardcoded AES-256 key.

T1486
Data Encrypted for Impact

Conti can use CreateIoCompletionPort(), PostQueuedCompletionStatus(), and GetQueuedCompletionPort() to rapidly encrypt files, excluding those with the extensions of .exe, .dll, and .lnk. It has used a different AES-256 encryption key per file with a bundled RAS-4096 public encryption key that is unique for each victim. Conti can use “Windows Restart Manager” to ensure files are unlocked and open for encryption.

T1489
Service Stop

Conti can stop up to 146 Windows services related to security, backup, database, and email solutions through the use of net stop.

View all 16 procedure examples

Groups that use it1

Campaigns1

References3

  1. CarbonBlack Conti July 2020 Open source
    Baskin, B. (2020, July 8). TAU Threat Discovery: Conti Ransomware. Retrieved February 17, 2021.
  2. Cybereason Conti Jan 2021 Open source
    Rochberger, L. (2021, January 12). Cybereason vs. Conti Ransomware. Retrieved February 17, 2021.
  3. Cybleinc Conti January 2020 Open source
    Cybleinc. (2021, January 21). Conti Ransomware Resurfaces, Targeting Government & Large Organizations. Retrieved April 13, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.