HomeSecurityConti ransomware: Renames itself into smaller units and continues

Conti ransomware: Renames itself into smaller units and continues

After its infrastructure was shut down by cybersecurity researchers, the notorious Conti ransomware gang has officially shut down , with its main operators declaring that the brand no longer exists.

See also: US: $15 million reward for information on Conti ransomware group

Conti

This news was shared on Twitterby Yelisey Boguslavskiy of Advanced Intel.

While the public “Conti News” data leaks and ransom negotiation sites are still online, Boguslavskiy said that the Tor used by members to conduct negotiations and post “news” on the data leak site are now offline.

According to Boguslavskiy, however, members of the Conti group were transferred to other, smaller ransomware operations.

And while the Conti ransomware brand no longer exists, the group will continue to play a significant role in the ransomware industry for a long time yet.

Boguslavskiy said that rather than rebranding itself as another large ransomware operation, Conti's leadership collaborated with other smaller ransomware gangs to carry out attacks.

See also: Connection found between Karakurt group and Conti ransomware

As part of this partnership, smaller ransomware gangs gain an influx of experienced Conti infiltrators, negotiators, and operators. The Conti team gains mobility and greater coverage from law enforcement.

ransomware

The Advanced Intel report explains that the Conti group has worked with numerous well-known ransomware operations, including HelloKitty, AvosLocker, Hive, BlackCat, BlackByte and others.

Existing Conti members, including negotiators, Intel analysts, handlers, and programmers, are distributed to other ransomware operations. While these members will now use the cryptojacking and trading sites of these other ransomware groups, they are still part of Conti for cybercrime.

Advanced Intel also states that new autonomous Conti member groups have been created that focus solely on data extraction rather than data encryption. Some of these groups include Karakurt, BlackByte, and Bazarcall.

See also: Conti ransomware: Is it related to the cyberattack on Nordex?

These initiatives allow the existing group to continue operating but no longer under the name Cοnti.

The rebranding of Conti is not a surprise for the researchers and journalists who have been monitoring them for the past months, if not the past years.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS