Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

CONTI · Threat actor profile

// THREAT ACTOR

CONTI_

Active

Conti was a Russian-speaking ransomware cartel that ran one of the most aggressive double-extortion operations between 2020 and 2022, targeting hospitals, government agencies, and critical infrastructure. The group disbanded publicly after the “Conti Leaks” exposed its internal chats and source code in early 2022, though many of its operators are believed to have rebranded into successor groups including Black Basta, Royal, and Karakurt.

For Ransomnews editorial coverage of CONTI — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.

293 Victims tracked
1 / 9 Active mirrors
2021-09-09 First listing
2022-06-07 Most recent

Victims by year

  • 2022 123
  • 2021 170

Leak site mirrors

9 mirrors tracked, 1 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.

  • continewsnv5otx5kaoje7krkto2qbu3gtqef22mnr7eaxw3y6ncz3ad.onion CONTI.News snapshot · 2022-06-21 19:12
  • continews.click continews.click | 522: Connection timed out snapshot · 2026-08-06 21:12
  • m232fdxbfmbrcehbrj5iayknxnggf6niqfj6x4iedrgtab4qupzjlaid.onion snapshot · 2024-12-06 21:45
  • contirec7nchr45rx6ympez5rjldibnqzh7lsa56lvjvaeywhvoj3wad.onion snapshot · 2024-12-06 21:46
  • contirecj4hbzmyzuydyzrvm2c65blmvhoj2cvf25zqj2dwrrqcq5oad.onion snapshot · 2024-12-06 21:46
  • contirecj4hbzmyzuydyzrvm2c65blmvhoj2cvf25zqj2dwrrqcq5oad.onion snapshot · 2024-12-12 16:26
  • contirecovery.best snapshot · 2024-12-12 16:27
  • contirecovery.top snapshot · 2024-12-12 16:30
  • htcltkjqoitnez5slo7fvhiou5lbno5bwczu7il2hmfpkowwdpj3q2yd.onion snapshot · 2025-07-08 17:46

Recent victims

The 50 most recent victims claimed by CONTI. Total in the index: 293.

Date listed Victim Description
2022-06-07 Alliance Steel
2022-06-02 Elevate Services
2022-05-26 Azimut Benetti Group
2022-05-25 LCRD
2022-05-25 MJH Life Sciences
2022-05-25 PFC USA
2022-05-25 The Contact Company
2022-05-24 Central Restaurant Products
2022-05-24 Schaumburg Park District
2022-05-24 RateGain
2022-05-23 Pianca
2022-05-23 Midea Carrier
2022-05-23 Imenco AS
2022-05-23 Royal Brunei Airlines Sdn Bhd
2022-05-23 Critical Content
2022-05-23 Automobil Holding AS
2022-05-23 Concepts in Millwork
2022-05-23 Eurofred
2022-05-23 Agile Sourcing Partners
2022-05-23 Alimentos y Frutos S.A.
2022-05-23 Worksoft
2022-05-23 Allcat Claims Service
2022-05-23 Omicron Consulting S.r.L
2022-05-17 FOR BlackCat and LockBit advert
2022-05-14 For Costa Rica and US terrorists (Biden and his administration)
2022-05-12 Cjk Group, Inc.
2022-05-04 EYP
2022-04-28 LARON an otp industrial solutions company
2022-04-27 Attica Holdings S.A.
2022-04-27 For Peru
2022-04-25 Elgin_Ca
2022-04-23 Jasec
2022-04-21 Managed Business Solutions
2022-04-20 Attica Group
2022-04-20 Instituto Meteorológico Nacional and racsa.go.cr
2022-04-19 GIBSON HomeWares
2022-04-19 Del Sol
2022-04-19 panasonic
2022-04-19 Milan Institute
2022-04-19 For Costa Rica
2022-04-18 Centris
2022-04-18 Barwick Bathroom Distribution LLP
2022-04-18 Nordex SE
2022-04-17 Lowell
2022-04-16 Tucker Door & Trim
2022-04-16 Ministerio de Hacienda - República de Costa Rica
2022-04-16 Parker Appliance Company
2022-04-15 Wocklum Group
2022-04-15 [IMPORTANT ANNOUNCEMENT!]
2022-04-15 Eminox

← Back to Ransomtracker

Statistics on this page are computed by Ransomnews from a live leak-site monitoring feed. Numbers update every ten minutes. Operator-written victim descriptions are truncated and shown in snippet form only. Source data: RansomLook (CC BY 4.0), aggregated and adapted by Ransomnews.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.