National Cyber Warfare Foundation (NCWF)

Conti


0 user ratings
2024-06-19 14:53:28
blscott

 - archive -- 
Conti is one of the largest RaaS ransomware hacker groups in existence. This group is known to be behind many high-profile hacks that have affected notable companies, Peru’s and Costa Rica’s governments, multiple retailers, and the Irish healthcare service. In early May 2022, the US government promised up to a $10 million reward for information about Conti.

Besides gaining access to a victim’s network, encrypting essential files or services, and demanding ransom in exchange, Conti makes sure that the ransomware spreads further. In short, it shares access to extremely damaging ransomware with partners in return for a share of the ransom payments collected, making the malicious software available to other hacking groups.

Conti is an advanced persistent threat (APT) that has been active since at least 2013 and targets government, military, defense contractors, telecommunications companies, and other organizations in various countries around the world. It is believed to be operated by a nation-state actor with ties to China's People's Liberation Army (PLA). Conti has been linked to several high-profile cyber attacks, including the 2017 WannaCry ransomware attack and the 2018 Petya/NotPetya ransomware outbreak. The group is known for its stealthy tactics, use of custom malware, and ability to remain undetected in compromised networks for extended periods of time.

Techniques, tactics and practices:

Conti is a highly sophisticated threat actor that employs several advanced techniques to achieve its objectives. Some of these include:

1. Stealthy tactics - The group uses stealthy tactics such as spear-phishing emails, watering hole attacks and other social engineering methods to gain initial access into targeted networks. They also use custom malware that is designed to evade detection by security software.
2. Custom malware - Conti has been known to develop its own custom malware for specific targets. This allows them to remain undetected in compromised networks and carry out their objectives without being detected.
3. Remote access tools (RATs) - The group uses RATs such as Mimikatz, PsExec, and Metasploit to gain remote access into targeted systems. They also use custom-built RATs that are designed specifically for their operations.
4.



Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.