Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-02

Conti

Also known as:Wizard SpiderGold UlrickTrickBot GangConti TeamRyuk operators

As of 2026-06-30, Conti is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware, ransomware. Also known as Wizard Spider, Gold Ulrick, TrickBot Gang, Conti Team. ATT&CK coverage spans 62 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1105 (Ingress Tool Transfer), T1003.001 (LSASS Memory), T1021.001 (Remote Desktop Protocol).

Tracked threats
31 critical · 2 high
First seen
2026-02-16
Last seen
2026-06-30
ATT&CK techniques
62across 3 of 3 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 3 tracked threat(s) · Categories: MALWARE, RANSOMWARE

Activity timeline

Conti appears in 3 tracked threats between and ; the busiest month was 2026-06 with 2 reports.

ATT&CK techniques observed

62 techniques observed across 3 of 3 tracked threats · Command and Control (13), Stealth (formerly Defense Evasion) (8), Discovery (7), Resource Development (7), Execution (5), Initial Access (5)
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
  • T1003.001 LSASS Memory — Credential Accessobserved in 2 of 3 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 2 of 3 tracked threats
  • T1046 Network Service Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 3 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 2 of 3 tracked threats
  • T1095 Non-Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
  • T1133 External Remote Services — Persistenceobserved in 2 of 3 tracked threats
  • T1219 Remote Access Tools — Command and Controlobserved in 2 of 3 tracked threats
  • T1486 Data Encrypted for Impact — Impactobserved in 2 of 3 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 3 tracked threats
  • T1001 Data Obfuscation — Command and Controlobserved in 1 of 3 tracked threats
  • T1001.003 Protocol or Service Impersonation — Command and Controlobserved in 1 of 3 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 3 tracked threats

Tracked threats