WIZARD_SPIDER__2021__Conti-Ransomware.pdf
ID: 51c17e2a-1145-4d18-bf6f-5adbe0153505
STIX ID: report--51c17e2a-1145-4d18-bf6f-5adbe0153505
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2021-02-04
Last Modified Date: 2021-02-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ClearSky/Whitestream analyze the CONTI ransomware operation, tracing its ties to Wizard Spider and Ryuk via bitcoin wallets, and chronicle a real-time negotiation with a victim that includes ransom demands, evidence of data exfiltration, and delivery of a decryptor, illustrating a sophisticated ransomware-as-a-service campaign and its financial flows across Binance and Rocketr.net.
