Conti is an advanced persistent threat (APT) that has been active since at least 2013 and targets government, military, defense contractors, telecommunications companies, and other organizations in various countries around the world. It is believed to be operated by a nation-state actor with ties to China's People's Liberation Army (PLA). Conti has been linked to several high-profile cyber attacks, including the 2017 WannaCry ransomware attack and the 2018 Petya/NotPetya ransomware outbreak. The group is known for its stealthy tactics, use of custom malware, and ability to remain undetected in compromised networks for extended periods of time.
Techniques, tactics and practices:
Conti is a highly sophisticated threat actor that employs several advanced techniques to achieve its objectives. Some of these include:
1. Stealthy tactics - The group uses stealthy tactics such as spear-phishing emails, watering hole attacks and other social engineering methods to gain initial access into targeted networks. They also use custom malware that is designed to evade detection by security software.
2. Custom malware - Conti has been known to develop its own custom malware for specific targets. This allows them to remain undetected in compromised networks and carry out their objectives without being detected.
3. Remote access tools (RATs) - The group uses RATs such as Mimikatz, PsExec, and Metasploit to gain remote access into targeted systems. They also use custom-built RATs that are designed specifically for their operations.
4.
