---
title: CONTI Group - The not so advanced APT
description: Recently in the news it was revealed that a member of an “APT” group that utilises the “Conti” ransomware became disgruntled at the state of their rel
image: https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/spider-hacker-01-1024x572.jpg
---

[Go Back Up](https://www.alchemysec.com.au/blog/conti-group-the-not-so-advanced-apt#top)

[Skip to Content](https://www.alchemysec.com.au/blog/conti-group-the-not-so-advanced-apt#body)

**University of Sydney Code Library Breach:** Disclosed 18 Dec, 2025

Personal details of about 27,500 current and former staff exposed.

18 Dec 2025 - Syd Uni breached

[Read more](https://www.sydney.edu.au/news-opinion/news/2025/12/18/notification-of-cyber-and-data-breach.html)

[![Alchemy\_Security\_Consulting\_Logo\_B2\_Cropped\_White\_400](https://www.alchemysec.com.au/hs-fs/hubfs/Alchemy_Security_Consulting_Logo_B2_Cropped_White_400.png?width=200&name=Alchemy_Security_Consulting_Logo_B2_Cropped_White_400.png)](https://www.alchemysec.com.au/)

- Offensive Security
- Defensive Security
- Managed Services
- Company
- Resources

[Have you been breached?](https://www.alchemysec.com.au/breached) [Book a consult](https://www.alchemysec.com.au/contact)

[Offensive Security](https://www.alchemysec.com.au/services/offensive) [Penetration Testing](https://www.alchemysec.com.au/services/offensive/pentest) [Red Teaming](https://www.alchemysec.com.au/services/offensive/red-teaming) [Adversary Simulation](https://www.alchemysec.com.au/services/offensive/adversary-simulation) [Purple Teaming](https://www.alchemysec.com.au/services/offensive/purple-teaming)

[Defensive Security](https://www.alchemysec.com.au/services/defensive) [Incident Response](https://www.alchemysec.com.au/breached) [SIEM, Logging & Detection Engineering](https://www.alchemysec.com.au/services/defensive/siem-logging)

[Managed Services](https://www.alchemysec.com.au/services/managed) [Managed Detection & Response](https://www.alchemysec.com.au/services/managed/mdr) [Managed SOC](https://www.alchemysec.com.au/services/managed/soc) [Continuous Threat Emulation](https://www.alchemysec.com.au/services/managed/continuous-threat-emulation)

[About Us](https://www.alchemysec.com.au/about) [Contact Us](https://www.alchemysec.com.au/contact)

[Blog](https://www.alchemysec.com.au/blog)

- Offensive Security
  
  [Offensive Security](https://www.alchemysec.com.au/services/offensive) [Penetration Testing](https://www.alchemysec.com.au/services/offensive/pentest) [Red Teaming](https://www.alchemysec.com.au/services/offensive/red-teaming) [Adversary Simulation](https://www.alchemysec.com.au/services/offensive/adversary-simulation) [Purple Teaming](https://www.alchemysec.com.au/services/offensive/purple-teaming)
- Defensive Security
  
  [Defensive Security](https://www.alchemysec.com.au/services/defensive) [Incident Response](https://www.alchemysec.com.au/breached) [SIEM, Logging & Detection Engineering](https://www.alchemysec.com.au/services/defensive/siem-logging)
- Managed Services
  
  [Managed Services](https://www.alchemysec.com.au/services/managed) [Managed Detection & Response](https://www.alchemysec.com.au/services/managed/mdr) [Managed SOC](https://www.alchemysec.com.au/services/managed/soc) [Continuous Threat Emulation](https://www.alchemysec.com.au/services/managed/continuous-threat-emulation)
- Company
  
  [About Us](https://www.alchemysec.com.au/about) [Contact Us](https://www.alchemysec.com.au/contact)
- Resources
  
  [Blog](https://www.alchemysec.com.au/blog)

[Have you been breached?](https://www.alchemysec.com.au/breached) [Book a consult](https://www.alchemysec.com.au/contact)

# CONTI Group - The not so advanced APT

[Blog](https://www.alchemysec.com.au/blog/tag/blog) [Defence](https://www.alchemysec.com.au/blog/tag/defence) 30 August 2021 [Alex](https://www.alchemysec.com.au/blog/author/alex) 4 min read

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/spider-hacker-01-1024x572.jpg?width=1000&name=spider-hacker-01-1024x572.jpg)

<https://twitter.com/intent/tweet/?text=CONTI+Group+-+The+not+so+advanced+APT&url=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fconti-group-the-not-so-advanced-apt> <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fconti-group-the-not-so-advanced-apt> <https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fconti-group-the-not-so-advanced-apt> [mailto:?subject=CONTI%20Group%20-%20The%20not%20so%20advanced%20APT&body=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fconti-group-the-not-so-advanced-apt](mailto:?subject=CONTI%20Group%20-%20The%20not%20so%20advanced%20APT&body=https%3A%2F%2Fwww.alchemysec.com.au%2Fblog%2Fconti-group-the-not-so-advanced-apt)

Recently in the news it was revealed that a member of an “APT” group that utilises the “Conti” ransomware became disgruntled at the state of their relationship with the group and leaked a large majority of the groups “Tools, Techniques and Procedures” documents.

Conti was first discovered in 2020 and is used primarily by the Russian crime group aliased as “Wizard Spider” (we will assume the leak came from a former member of this group). In addition to the encryption of files seen from historical families of ransomware, Conti also copies files to the attacker’s server before encryption, allowing the group to threaten data leaks if the ransom isn’t paid.

As we regularly hear of organisations succumbing to Conti infections or targeted by “Advanced Persistent Threats” such as Wizard Spider, I was curious as to how the group operates so successfully in compromising these organisations and delivering their payloads. In the name of science\*, I obtained a copy of the leaked files and to my dismay discovered they really aren’t so “advanced” in the way they operate.

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture1-1.png?width=601&height=92&name=Picture1-1.png)

 Figure 1 - Downloading the leak "for science"

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture2-1.png?width=1378&height=377&name=Picture2-1.png)

 Figure 2 - Archive Contents

From what I can gather based on a Google translate of the leaked documents, activities tend to follow that of a standard penetration test, and they don’t seem to employ any advanced methods such as EDR evasion or attempt to hide their tracks long term which is kind of what you’d expect from a group labelled “advanced”. Organisations can take comfort that they don’t generally seem to utilise 0-day exploits but may jump on easily exploitable vulnerabilities that have recently been disclosed (install those patches!).

## Initial Compromise

The group seems to have the most success in gaining an initial foothold through phishing, although have been seen brute forcing RDP end points exposed to the Internet. Often, they will attempt to directly just drop an executable file on a user’s machine via a malicious, disguised email attachment, which will beacon back to a command-and-control server (currently the IcedID malware).

This initial beacon then appears to be used to pull down a Cobalt Strike implant that is then used for the rest of the engagement.

## Lateral Movement

Once the initial foothold has been gained, and the switch to Cobalt Strike has occurred, internal enumeration activities begin. Activities include enumeration of compromised user privileges on the local machine, identification of domain administrators, and open SMB shares.

During this phase, a lot of their activity is detectable if appropriate systems and alerts are in place. The group utilises several additional binaries such as “Adfind”, “Anydesk”, and “putty” which write artifacts to disk. In addition, widely available free scripts are used from projects such as Powerview or Bloodhound.

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture3-1.png?width=601&height=374&name=Picture3-1.png)

 Figure 3 - Anydesk remote desktop configuration

## Privilege Escalation

Attackers won’t necessarily perform lateral movement and privilege escalation once gaining an initial foothold, but once they start, they move quickly. Entire environment compromises have been reported in as quickly as 2 hours.

Privilege escalation doesn’t follow anything special, simply determining the best route to obtain administrator or higher privileges on the local machine, identifying domain administrator groups and then using well known tools to find where these users are logged in and compromising these systems to obtain their passwords/password hashes.

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/Picture4-1.png?width=601&height=462&name=Picture4-1.png)

 Figure 4 - Helpful instruction on hunting down admins

Once they have domain administrator privileges, they will exfiltrate company data (Office files etc.) offsite for use in blackmail at a later stage. After this they will drop Conti ransomware on the network, encrypting all files on the file share(s) and as many workstations as are reachable.

## Detection and Prevention

The primary thread running through the leak is of a few people with *a bit more* experience writing basic guides for those *not so experienced*, and in performing IR for organisations compromised by Wizard Spider we have discovered that this seems to be the case.

Very little is information is provided for advanced exploitation techniques, stealth and remaining out of site or compromising even a semi-mature environment (ie. MFA and EDR or application whitelisting).

Organisations can greatly reduce the likelihood of compromise through investment in a couple of key areas. By implementing multi-factor authentication to prevent compromised credentials being re-used. Implementing application whitelisting configured to only allow approved binaries such as Microsoft-signed will prevent the malware from running all together in the event a user clicks on a link or opens an attachment.

In addition, implementing an Endpoint Detection and Response (EDR) will prevent “living off the land” style attacks that are consistent with exploitation behaviour.

For a long-term approach, organisations can follow the ACSC’s Essential 8 list of recommended security protections.

## Disclaimer

I make no promises regarding organisation security when defending against an actual “advanced” threat such as a state-sponsored attacker tasked with infiltrating your organisation with specific goals in mind.

## References

https://www.nbcnews.com/tech/security/step-1-google-search-ransomware-hacker-goes-rogue-leaks-gangs-plan-rcna1611  
https://thedfirreport.com/2021/05/12/conti-ransomware/  
https://www.cyber.gov.au/acsc/view-all-content/essential-eight

## Alex

## Ready to Transform your Business with Little Effort Using Brightlane?

[Register Now](https://www.example.com)

You May Like These

## Related Articles

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/envelope-01-1024x572.jpg?width=700&name=envelope-01-1024x572.jpg)

### [Please Sign Here - Why NTLM Relaying Is Still a Risk in 2021](https://www.alchemysec.com.au/blog/please-sign-here-why-ntlm-relaying-is-still-a-risk-in-2021)

![](https://www.alchemysec.com.au/hs-fs/hubfs/Imported_Blog_Media/chris-yang-1tnS_BVy9Jk-unsplash-1024x683-1.jpg?width=700&name=chris-yang-1tnS_BVy9Jk-unsplash-1024x683-1.jpg)

### [OSINT for Penetration Testers](https://www.alchemysec.com.au/blog/osint-for-penetration-testers)

![](https://www.alchemysec.com.au/hs-fs/hubfs/Images/Blog/padlock-2400.jpg?width=700&name=padlock-2400.jpg)

### [Yes, Local Administrators ARE a Risk](https://www.alchemysec.com.au/blog/yes-local-administrators-are-a-risk)

---

![Alchemy Security Consulting](https://www.alchemysec.com.au/hubfs/Images/Logos/Alchemy/Alchemy_Security_Consulting_Logo_B2_Cropped_White_350.png)

 Offensive, defensive and managed security expertise to help you understand your exposure, strengthen your defences and validate improvement.

#### Get In Touch

##### Location

 30 Pirie St, Adelaide, South Australia 5000

##### Contact

###### Phone :

[1300 792 870](tel:+611300792870)

###### Email :

[sales@alchemysec.com.au](mailto:sales@alchemysec.com.au)

#### Services

- [Penetration Testing](https://www.alchemysec.com.au/services/offensive/pentest)
- [Red Teaming](https://www.alchemysec.com.au/services/offensive/red-teaming)
- [Adversary Simulation](https://www.alchemysec.com.au/services/offensive/adversary-simulation)
- [Purple Teaming](https://www.alchemysec.com.au/services/offensive/purple-teaming)
- [Incident Response](https://www.alchemysec.com.au/breached)
- [SIEM, Logging & Detection Engineering](https://www.alchemysec.com.au/services/defensive/siem-logging)
- [Managed Detection & Response](https://www.alchemysec.com.au/services/managed/mdr)
- [Managed SOC](https://www.alchemysec.com.au/services/managed/soc)
- [Continuous Threat Emulation](https://www.alchemysec.com.au/services/managed/continuous-threat-emulation)

#### Company

- [About Us](https://www.alchemysec.com.au/about)
- [Blog](https://www.alchemysec.com.au/blog)
- [Contact](https://www.alchemysec.com.au/contact)
- [Book a Consult](https://www.alchemysec.com.au/contact)
- [Privacy Policy](https://www.alchemysec.com.au/privacy-policy)

© Alchemy Security. All rights reserved | [Privacy Policy](https://www.alchemysec.com.au/privacy-policy)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Alex",
    "url" : "https://www.alchemysec.com.au/blog/author/alex"
  },
  "dateModified" : "2026-09-30T10:35:08.751Z",
  "datePublished" : "2021-08-30T04:00:00.000Z",
  "headline" : "CONTI Group - The not so advanced APT",
  "image" : [ "https://www.alchemysec.com.au/hubfs/Imported_Blog_Media/spider-hacker-01-1024x572.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.alchemysec.com.au/blog/conti-group-the-not-so-advanced-apt",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.alchemysec.com.au/hubfs/Alchemy_Security_Consulting_Logo_B2_Cropped_White_300.png"
    }
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://alchemysec.com.au/#organization",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "AU",
    "addressLocality" : "Adelaide",
    "addressRegion" : "SA",
    "postalCode" : "5000",
    "streetAddress" : "30 Pirie St"
  },
  "description" : "Cybersecurity consultancy providing offensive security, defensive security and managed security services.",
  "email" : "sales@alchemysec.com.au",
  "name" : "Alchemy Security Consulting",
  "telephone" : "+611300792870",
  "url" : "https://alchemysec.com.au/"
}
```