🇷🇺Conti
🇷🇺 Conti is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 26 detection use cases to this actor across 80 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-25 to 2026-07-25.
crit 1
26Use cases
1Articles
80Techniques
0IOCs
Known aliases
ContiWizard SpiderTrickBot GroupGOLD ULRICKUNC1878TEMP.MixMasterGrim SpiderFIN12GOLD BLACKBURNITG23Periwinkle TempestDEV-0193Pistachio TempestDEV-0237
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.002 · Security Account ManagerT1003.003 · NTDST1005 · Data from Local SystemT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021 · Remote ServicesT1021.002 · SMB/Windows Admin SharesT1021.006 · Windows Remote ManagementT1027 · Obfuscated Files or InformationT1027.010 · Command ObfuscationT1033 · System Owner/User DiscoveryT1036.004 · Masquerade Task or ServiceT1041 · Exfiltration Over C2 ChannelT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.001 · Dynamic-link Library InjectionT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1070.001 · T1070.001T1070.004 · File DeletionT1071.001 · Web ProtocolsT1074 · Data StagedT1074.001 · Local Data StagingT1078 · Valid AccountsT1078.002 · Domain AccountsT1082 · System Information DiscoveryT1087.002 · Domain AccountT1098.001 · Additional Cloud CredentialsT1105 · Ingress Tool TransferT1112 · Modify RegistryT1133 · External Remote ServicesT1135 · Network Share DiscoveryT1136.001 · Local AccountT1136.002 · Domain AccountT1176 · Software ExtensionsT1197 · BITS JobsT1204.001 · Malicious LinkT1204.002 · Malicious FileT1210 · Exploitation of Remote ServicesT1218 · System Binary Proxy ExecutionT1218.011 · Rundll32T1219 · Remote Access ToolsT1222.001 · Windows PermissionsT1486 · Data Encrypted for ImpactT1489 · Service StopT1490 · Inhibit System RecoveryT1518.001 · Security Software DiscoveryT1518.002 · Backup Software DiscoveryT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1547.004 · Winlogon Helper DLLT1550.002 · Pass the HashT1552.006 · Group Policy PreferencesT1553.002 · Code SigningT1555.003 · Credentials from Web BrowsersT1555.004 · Windows Credential ManagerT1557.001 · Name Resolution Poisoning and SMB RelayT1558.003 · KerberoastingT1560.001 · Archive via UtilityT1562.001 · T1562.001T1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1585.002 · Email AccountsT1588.002 · ToolT1588.003 · Code Signing CertificatesT1685 · Disable or Modify Tools