TTP Tuesday: Conti (Release 6)
15 February 2022
We're releasing the final instalment of our Conti ransomware theme with new TTPs focused on Windows ransomware deployment. To date, our Conti theme now contains the following kill-chains:
Deploy ransomware (Current Release)
Conti is considered Ransomware-as-a-Service (RaaS) and has an elaborate chain of events from initial access to execution of the ransomware. For this week, we are focusing on ransomware deployment techniques. The chain with resizing and deleting VSS shadow copies to make data recovery more difficult. Next, disarmed Conti malware (Conti samples modified such that they will not encrypt files when executed) is deployed on the host. Once the disarmed malware is deployed, Prelude’s GoRansom agent is staged and executed to simulate the Conti file encryption process. Finally, Conti ransom note variants are dropped on the victim hosts.
Check it out on the Prelude chains website.
Watch a demonstration:
Next week, we will be releasing the first part of a brand new series.
Staying up to date
Thanks for reading our latest TTP Tuesday release! Please subscribe and reach out with any feedback. We love to hear from our community!
There are several ways to follow us and learn more about Prelude and our team members:
Get our products
Download Prelude Operator: https://www.prelude.org/download
See the latest kill chain and TTP Releases: https://chains.prelude.org/
See our open-source repositories: https://github.com/preludeorg
Join our community
Read, watch, and listen
Listen to our Podcast: https://anchor.fm/preludeorg
Read our blog: https://feed.prelude.org
Watch our live streams: https://www.twitch.tv/preludeorg
Watch our pre-recorded content: https://www.youtube.com/channel/UCZyx-PDZ_k7Vuzyqr4-qK9A
Follow our team