Conti (ransomware)
ransomware group targeting primarily Microsoft products

Conti is malware developed and first used by the Russia-based hacking group "Wizard Spider" in December, 2019. It has since become a full-fledged ransomware-as-a-service (RaaS) operation used by numerous threat actor groups to conduct ransomware attacks.
Conti malware, once deployed on a victim device, not only encrypts data on the device but also spreads to other devices on the network, obfuscates its presence, and provides a remote attacker control over its actions on the objective. All versions of Microsoft Windows are known to be affected. The United States government offered a reward of up to $10 million for information on the group in early May 2022.
Description
RaaS model
According to a leaked playbook, core team-members of a Conti operation manage the malware itself, while recruited affiliates are tasked with exploitation of victim networks and encryption of their devices.
Conti's ransomware as a service model varies in its structure from a typical affiliate model. Unlike other RaaS models, groups using the Conti model likely pay deployers of the malware in wages rather than in a percentage of the ransom (once paid). Conti operators have also been known to use double-extortion as a means to pressure victims into paying, including publishing the victim's stolen data. In cases where a victim organization refuses to pay, they have sold access to the organization to other threat actors.
Begin with the source’s own compact description: “Conti (ransomware)” is ransomware group targeting primarily Microsoft products. The dossier treats that line as a proposition to test through Conti, ransomware and group, not as a finished interpretation.
Why this record matters
The phrase “ransomware group targeting primarily Microsoft products” supplies a clear boundary for inquiry. It also exposes the unanswered questions: who defined that boundary, when it became stable and which sources sit outside it.
Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Sep 16, 2026. The linked authority identifier is Q106833920. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2019 and 2022.
A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “Conti (ransomware)”, its source revision and the description used here.
- Expand the search: follow Conti (ransomware) primary sources, Conti (ransomware) archive and Conti research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Conti (ransomware)”?
- What terminology or title could unlock a more precise catalogue search?
- Which cited source is closest to the event, object or claim?
Search terms from this dossier
This entry incorporates text from “Conti (ransomware)” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.