# Conti

> As of 2026-06-30, Conti is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware, ransomware. Also known as Wizard Spider, Gold Ulrick, TrickBot Gang, Conti Team. ATT&CK coverage spans 62 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1105 (Ingress Tool Transfer), T1003.001 (LSASS Memory), T1021.001 (Remote Desktop Protocol).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** MALWARE, RANSOMWARE
- **Also known as:** Wizard Spider, Gold Ulrick, TrickBot Gang, Conti Team, Ryuk operators
- **As of:** 2026-06-30

## ATT&CK techniques observed

62 techniques observed across 3 of 3 tracked threats. Tactics: Command and Control (13), Stealth (formerly Defense Evasion) (8), Discovery (7), Resource Development (7), Execution (5), Initial Access (5).

- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 3 tracked threats
- [T1003.001](https://intel.threadlinqs.com/technique/T1003.001) LSASS Memory — Credential Access — observed in 2 of 3 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 2 of 3 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 3 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 3 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 3 tracked threats
- [T1095](https://intel.threadlinqs.com/technique/T1095) Non-Application Layer Protocol — Command and Control — observed in 2 of 3 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Persistence — observed in 2 of 3 tracked threats
- [T1219](https://intel.threadlinqs.com/technique/T1219) Remote Access Tools — Command and Control — observed in 2 of 3 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 2 of 3 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 2 of 3 tracked threats
- [T1001](https://intel.threadlinqs.com/technique/T1001) Data Obfuscation — Command and Control — observed in 1 of 3 tracked threats
- [T1001.003](https://attack.mitre.org/techniques/T1001/003/) Protocol or Service Impersonation — Command and Control — observed in 1 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 3 tracked threats

## Tracked threats

- [SystemBC (Coroxy) Malware: Tor-Based SOCKS5 Proxy Backdoor Enabling Ransomware Persistence and C2 Obfuscation](https://intel.threadlinqs.com/threat/TL-2026-1005) — CRITICAL
- [Conti Ransomware Malware Developer Oleksii Lytvynenko Pleads Guilty to Wire Fraud Conspiracy (DOJ, June 2026)](https://intel.threadlinqs.com/threat/TL-2026-0785) — HIGH
- [Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown Complexity](https://intel.threadlinqs.com/threat/TL-2026-0099) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Conti
