Conti (ransomware)

Conti is ransomware that has been observed since 2020.[1][2] All versions of Microsoft Windows are known to be affected.[1]

Threat details

The software uses its own implementation of AES-256 that uses up to 32 individual logical threads, making it much faster than most ransomware.[1] The method of delivery is not clear.[1]

The gang behind Conti has operated a site from which it can leak documents copied by the ransomware since 2020.[3] The same gang has operated the Ryuk ransomware.[3] The group is known as Wizard Spider and is based in Saint Petersburg, Russia.[4]

Behaviour

Once on a system it will try to delete Volume Shadow Copies.[1] It will try to terminate a number of services using Restart Manager to ensure it can encrypt files used by them.[1] It will disable real time monitor and uninstall the Windows Defender application. Default behaviour is to encrypt all files on local and networked Server Message Block drives, ignoring files with DLL, .exe, .sys and .lnk extensions.[1] It is also able to target specific drives as well as individual IP addresses.[1][2]

Remediation

According to NHS Digital the only guaranteed way to recover is to restore all affected files from their most recent backup.[1]

Research

VMware Carbon Black has published a technical report on the ransomware.[2][5]

Targets

See also

References

  1. "Conti Ransomware". NHS Digital. NHS Digital. 2020-07-09. Retrieved 2021-05-14.
  2. Cimpanu, Catalin (9 July 2020). "Conti ransomware uses 32 simultaneous CPU threads for blazing-fast encryption". ZDNet. Retrieved 14 May 2021.
  3. Cimpanu, Catalin (25 August 2020). "Conti (Ryuk) joins the ranks of ransomware gangs operating data leak sites". ZDNet. Retrieved 15 May 2021.
  4. Corfield, Gareth (14 May 2021). "Hospitals cancel outpatient appointments as Irish health service struck by ransomware". The Register. Retrieved 15 May 2021.
  5. Baskin, Brian (2020-07-08). "TAU Threat Discovery: Conti Ransomware". VMware Carbon Black. Retrieved 2021-05-14.
  6. "Waikato hospitals hit by cyber security incident". Radio New Zealand. 18 May 2021. Retrieved 18 May 2021.
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.