Activity timeline
Conti appears in 3 tracked threats between and ; the busiest month was 2026-06 with 2 reports.
ATT&CK techniques observed
- T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
- T1003.001 LSASS Memory — Credential Accessobserved in 2 of 3 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 2 of 3 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 2 of 3 tracked threats
- T1059.001 PowerShell — Executionobserved in 2 of 3 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 2 of 3 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 2 of 3 tracked threats
- T1095 Non-Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
- T1133 External Remote Services — Persistenceobserved in 2 of 3 tracked threats
- T1219 Remote Access Tools — Command and Controlobserved in 2 of 3 tracked threats
- T1486 Data Encrypted for Impact — Impactobserved in 2 of 3 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 2 of 3 tracked threats
- T1001 Data Obfuscation — Command and Controlobserved in 1 of 3 tracked threats
- T1001.003 Protocol or Service Impersonation — Command and Controlobserved in 1 of 3 tracked threats
- T1005 Data from Local System — Collectionobserved in 1 of 3 tracked threats
Tracked threats
- SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 ObfuscationCRITICAL
- Conti Ransomware Malware Developer Oleksii Lytvynenko Pleads Guilty to Wire Fraud Conspiracy (DOJ, June 2026)HIGH
- Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown ComplexityHIGH