Overview
Conti is a human operated ransomware family operated as ransomware-as-a-service by the Russia-based threat group tracked as Wizard Spider. First observed in December 2019, it evolved directly from the Ryuk ransomware codebase and rapidly became one of the most destructive and financially prolific ransomware operations on record. Between 2020 and May 2022, the group recorded an estimated $180 million in annual revenue at peak, with the FBI estimating cumulative payments exceeding $150 million across more than 1,000 confirmed victims.
Conti differs from most RaaS operations in how it compensated its workforce. Rather than splitting ransom proceeds with affiliates on a percentage basis, Conti paid operators fixed monthly wages, structuring itself more like a corporation than a criminal collective. Leaked internal communications from February 2022 revealed an organization of approximately 62 to over 100 personnel with dedicated roles spanning development, penetration testing, negotiation, and human resources.
The group's attack model combined established malware delivery infrastructure with hands-on post-exploitation. Initial access arrived through TrickBot and BazarLoader infections, which were used to stage Cobalt Strike beacons. From there, operators conducted Active Directory reconnaissance, harvested credentials using Mimikatz and related tooling, moved laterally via RDP and SMB, exfiltrated data using Rclone, then deployed Conti's multi-threaded encryption payload across the domain. The full chain from initial access to domain-wide encryption was documented in incidents lasting as few as 32 hours.
In February 2022, following Russia's invasion of Ukraine, Conti publicly announced its support for the Russian government. A Ukrainian affiliate responded by leaking over 60,000 internal chat messages, technical manuals, and source code. The reputational and operational damage was severe. Victims stopped paying, and the brand became a liability. By May 2022, Conti's infrastructure, including its leak site and negotiation portals, had been shut down. The group did not disappear. Its operators redistributed into successor groups including Black Basta, Karakurt, BlackByte, Royal, and Akira, carrying the same tooling, playbooks, and personnel. Those groups remain active.
CISA and the FBI jointly issued an advisory on Conti in September 2021, updated through March 2022, documenting over 400 attacks against US and international organizations. In September 2023, the US Department of Justice indicted four Russian nationals for their roles in the operation. A loader developer, Oleksii Lytvynenko, pleaded guilty in 2026 under FBI Operation Riptide.