What is Conti ransomware?
Definition, Legacy, and How Breach Containment Stops It
Conti is considered one of the first and most successful ransomware-as-a-service (RaaS) operations, operating roughly from 2020 to 2022 and notorious as one of the most damaging groups of its era. Conti's attacks were characterized by hands-on-keyboard access within an organization's networks. This allowed attackers to move through the network by hand, reaching high-value systems before encrypting them. Conti conducted most of its attacks on government agencies and healthcare organizations, which forced some of these entities to go offline for prolonged periods.
Key takeaways
- Conti was a ransomware-as-a-service operation active from about 2020 to 2022, run by a Russian-speaking group.
- It relied on manual, hands-on-keyboard lateral movement to reach critical systems before encrypting them.
- Conti carried out major attacks on healthcare and government, including national-scale disruptions.
- The operation shut down in 2022 after internal chat logs were leaked, and its members moved into successor groups.
- Microsegmentation removes the internal paths Conti operators used to move toward high-value systems.
Conti ransomware defined
The name Conti refers to both the ransomware itself and the cybercrime operation that ran it. The operation has been widely linked to a Russian-speaking threat group tracked as "Wizard Spider."
Conti operated as a ransomware-as-a-service (RaaS), with the primary group providing affiliates access to shared tooling and infrastructure while affiliates carried out the intrusions. Conti succeeded Ryuk, an earlier ransomware strain developed by the same network of operators.
Conti operators used an attack method known as double extortion. After stealing sensitive data and encrypting a victim's system, the group threatened to publish the data on a website known as a leak site unless payment was made.
How did Conti ransomware spread?
Conti spread through manual lateral movement after an initial foothold. Operators typically gained access through phishing, malicious loaders such as BazarLoader, or stolen credentials. Inside the network, they used tools including Cobalt Strike to map systems, harvest credentials, and move across hosts over administrative and remote-access protocols. They reached domain controllers and critical servers, then deployed the ransomware broadly.
This approach depended on the ability to move freely between systems once inside. Flat internal networks gave Conti operators a clear path from a single compromised workstation to the core of the environment.
What was the Conti ransomware business model?
Conti didn't operate like your typical hacking group. It ran like a legitimate organization with all of the functions you'd expect in a successful business, including payroll, performance reviews, and internal complaints about management. As reported by Krebs on Security in their analysis of the leaked Conti documents, the organizational structure included a hierarchy of coders, testers, negotiators, and administrative personnel. They were paid in cryptocurrency on a regular schedule, and reportedly some employees worked shifts and asked for time off.
This organizational structure is what allowed Conti to operate at scale. Chainalysis estimated that Conti generated nearly $180 million in cryptocurrency revenue during 2021, making it one of the highest-earning ransomware organizations at the time.
Conti used a ransomware-as-a-service affiliate model to scale the operation. The core team created and maintained the malware, while affiliates performed the intrusion and shared the ransom. They ran multiple attack campaigns at the same time and approached the breach and extortion process as a repeatable service.
How dangerous was Conti ransomware?
The damage Conti caused came from a combination of volume and precision. CISA and the FBI had identified more than 1,000 Conti attacks against U.S. and international organizations. When downtime, recovery, and ransom were factored in, the average Conti incident cost victims over $520,000, according to a Coveware report.
Hospitals and governmental agencies accounted for a large share of Conti's victims. The operators behind the group moved manually through networks, reaching domain controllers before anyone noticed the intrusion. That persistence and patience, along with the group's willingness to strike healthcare systems mid-pandemic, defined Conti as one of the most feared ransomware brands.
What were notable Conti attacks?
Conti was responsible for several high-impact attacks. In May 2021, it disrupted the Health Service Executive (HSE), Ireland's national health system, forcing a shutdown of IT systems across hospitals. In 2022, an attack on the government of Costa Rica led the country to declare a national state of emergency. These incidents showed how far a single intrusion could spread when internal movement went unchecked.
Is Conti ransomware still active?
Conti is no longer active under its own name. In early 2022, internal chat logs and source code were leaked publicly after the group voiced support for Russia during the invasion of Ukraine. The operation shut down later that year. Its members and tooling dispersed into successor operations, including Black Basta and BlackSuit, so the methods Conti refined continue in current ransomware activity.
What ransomware groups descended from Conti?
When Conti shut down in 2022, the underlying threat didn't disappear; it scattered. Former Conti members dispersed into new operations using the same tools and attack methods, but under different names.
The first group to emerge using this model was Black Basta. They launched in April 2022 using nearly the same double-extortion model Conti had. Royal followed a similar path, then rebranded as BlackSuit in 2023 after law enforcement pressure mounted. A joint federal advisory reported that Royal and BlackSuit collectively compromised over 450 U.S. victims since 2022 and demanded over $370 million in ransom money.
Black Basta, Royal, and BlackSuit continue to attack the healthcare, manufacturing, and critical infrastructure sectors that Conti targeted most heavily. The lesson from Conti's demise may be harsh - taking down a ransomware brand does little to disrupt the people or the playbook behind it, and both are likely to resurface elsewhere within months.
How do you contain a Conti-style attack?
You contain a Conti-style attack by closing the internal routes operators use to move toward critical systems. Because Conti relied on manual lateral movement, restricting east-west traffic directly limits how far an intrusion can reach.
Microsegmentation solutions permit only the connections each workload legitimately needs and block the administrative and remote-access protocols attackers use to travel between hosts. An operator who lands on one workstation finds the paths to domain controllers and critical servers already closed. The intrusion stays contained to a small area instead of reaching the core of the environment. This is breach containment applied to a hands-on-keyboard threat.
Frequently asked questions about Conti ransomware
What type of malware is Conti?
Conti was ransomware as a service (RaaS) - a model in which a core group rents its tooling to affiliates in exchange for a share of the ransom - specifically designed to perform double-extortion attacks, which combine encrypting a victim's data with stealing their sensitive information.
How did Conti spread across a network?
After Conti operators gained access through phishing or other threat vectors, they harvested credentials and used them to move from host to host inside the network. They then found and compromised domain controllers and other critical systems within the organization.
Is Conti still active?
No. Conti was shut down by its own members in 2022 when internal chat logs were compromised and leaked. After its demise, many of those individuals went on to create new, similar organizations, including Black Basta and BlackSuit.
Can microsegmentation stop a Conti-style attack?
Yes. Microsegmentation restricts east-west traffic and blocks the protocols operators use to move between hosts, containing the intrusion before it reaches critical systems.
.png)

.webp)
.webp)
.webp)
.webp)


.webp)






