Conti (ransomware)
Conti is ransomware that has been observed since 2020.[1][2] All versions of Microsoft Windows are known to be affected.[1]
Threat details
The software uses its own implementation of AES-256 that uses up to 32 individual logical threads, making it much faster than most ransomware.[1] The method of delivery is not clear.[1]
The gang behind Conti has operated a site from which it can leak documents copied by the ransomware since 2020.[3] The same gang has operated the Ryuk ransomware.[3] The group is known as Wizard Spider and is based in Saint Petersburg, Russia.[4]
Behaviour
Once on a system it will try to delete Volume Shadow Copies.[1] It will try to terminate a number of services using Restart Manager to ensure it can encrypt files used by them.[1] It will disable real time monitor and uninstall the Windows Defender application. Default behaviour is to encrypt all files on local and networked Server Message Block drives, ignoring files with DLL, .exe, .sys and .lnk extensions.[1] It is also able to target specific drives as well as individual IP addresses.[1][2]
Remediation
According to NHS Digital the only guaranteed way to recover is to restore all affected files from their most recent backup.[1]
Research
VMware Carbon Black has published a technical report on the ransomware.[2][5]
Targets
See also
- Health Service Executive cyberattack - involves a new variant of the ransomware.
- Wizard Spider - group known to use the software
References
- "Conti Ransomware". NHS Digital. NHS Digital. 2020-07-09. Retrieved 2021-05-14.
- Cimpanu, Catalin (9 July 2020). "Conti ransomware uses 32 simultaneous CPU threads for blazing-fast encryption". ZDNet. Retrieved 14 May 2021.
- Cimpanu, Catalin (25 August 2020). "Conti (Ryuk) joins the ranks of ransomware gangs operating data leak sites". ZDNet. Retrieved 15 May 2021.
- Corfield, Gareth (14 May 2021). "Hospitals cancel outpatient appointments as Irish health service struck by ransomware". The Register. Retrieved 15 May 2021.
- Baskin, Brian (2020-07-08). "TAU Threat Discovery: Conti Ransomware". VMware Carbon Black. Retrieved 2021-05-14.
- "Waikato hospitals hit by cyber security incident". Radio New Zealand. 18 May 2021. Retrieved 18 May 2021.