A lesser-known ransomware strain known as Conti uses up to 32 simultaneous CPU threads to encrypt files on infected computers for faster encryption speeds, security researchers from Carbon Black reported on Wednesday.
Conti is the latest in a long line of ransomware strains to be detected this year. Like most ransomware families today, Conti was designed to be directly controlled by an adversary, rather than executing automatically on its own.
These types of ransomware strains are also known as “manually operated ransomware” and are designed to be deployed during targeted attacks on large corporate or government networks.
Conti operates like most ransomware. However, it also comes with its own specifics, including some features not seen in other strains.

In a technical report published on Wednesday, Carbon Black's TAU says that the element that stood out during their analysis of Conti's code was its support for multi-threaded operations.
This is not entirely unique. Other ransomware strains also support operations , performing multiple simultaneous “computations” on the CPU to speed up their execution and allow the encryption process to complete more quickly before the file-locking operation is detected and stopped by antiviruses.
Other ransomware strains that use multiple CPU threads include REVIL (Sodinokibi), LockBit, Rapid, Thanos, Phobos, LockerGoga, and MegaCortex – to name a few. But Carbon Black says Conti stood out because of the large number of concurrent threads it used – namely, 32 – which resulted in “faster encryption compared to many other ransomware.”
However, that wasn't the only detail Carbon Black found in Conti. The second feature was a detailed inspection of the ransomware's encryption targets via a command-line client.
Carbon Black researchers say the ransomware can be configured to skip encrypting files on local drives and encrypt data on network SMB shares only by feeding the ransomware binary a list of IP addresses via the command line.
Furthermore, this behavior can also confuse security teams investigating such incidents, who may not be able to locate the point of entry into a network unless they conduct a full scan of all systems, allowing hackers to remain hidden within a single machine on the victim's network.
The third unique technique found in the Conti code is the abuse of the Windows Restart Manager – the Windows component that unlocks files before the operating system restarts.
According to Carbon Black, Conti calls this component to unlock and terminate application processes so that it can encrypt their corresponding data. This trick can be incredibly useful on Windows servers, where most sensitive data is managed by a database that is almost always running.
There is currently no way to recover files locked by Conti ransomware, which means that all known prevention methods – such as keeping offline backups, securing workstations, and open remote management ports – must be used.
