Skip to main content
  1. Home
  2. Computing
  3. News

Notorious ransomware gang Conti shuts down, but not for good

Add as a preferred source on Google

The ransomware group known as Conti has officially shut down, with all of its infrastructures now offline.

Although this might seem like good news, it’s only good on the surface — Conti is not over, it has simply split into smaller operations.

Conti split chart.
Advanced Intel

Conti was launched in the summer of 2020 as a successor to the Ryuk ransomware. It relied on partnerships with other malware infections in order to distribute. Malware such as TrickBot and BazarLoader was the initial point of entry for Conti, which then proceeded with the attack. Conti proved to be so successful that it eventually evolved into a cybercrime syndicate that took over TrickBot, BazarLoader, and Emotet.

Recommended Videos

During the past two years, Conti carried out a number of high-profile attacks, targeting the City of Tulsa, Advantech, and Broward County Public Schools. Conti also held the IT systems of Ireland’s Health Service Executive and Department of Health ransom for weeks and only let go when they were facing serious trouble from law enforcement around the world. However, this attack gave Conti a lot of attention from the global media.

Most recently, it targeted the country of Costa Rica, but according to Yelisey Bogslavskiy of Advanced Intel, the attack was just a cover-up for the fact that Conti was disbanding the whole operation. Boguslavskiy told Bleeping Computer that the attack on Costa Rica was made so public in order to give the members of Conti time to migrate to different ransomware operations.

“The agenda to conduct the attack on Costa Rica for the purpose of publicity instead of ransom was declared internally by the Conti leadership. Internal communications between group members suggested that the requested ransom payment was far below $1 million (despite unverified claims of the ransom being $10 million, followed by Conti’s own claims that the sum was $20 million),” says a yet-to-be-published report from Advanced Intel, shared ahead of time by Bleeping Computer.

Conti ransomware group logo.
BleepingComputer

The ultimate end to Conti was brought on by the group’s open approval of Russia and its invasion of Ukraine. On official channels, Conti went as far as to say that it will pool all of its resources into defending Russia from possible cyberattacks. Following that, a Ukrainian security researcher leaked over 170,000 internal chat messages between the members of the Conti group, and ultimately also leaked the source code for the gang’s ransomware encryptor. This encryptor was later used to attack Russian entities.

As things stand now, all of Conti’s infrastructure has been taken offline, and the leaders of the group said that the brand is over. However, this doesn’t mean that Conti members will no longer pursue cybercrime. According to Boguslavskiy, the leadership of Conti decided to split up and team up with smaller ransomware gangs, such as AvosLocker, HelloKitty, Hive, BlackCat, and BlackByte.

Members of the previous Conti ransomware gang, including intel analysts, pentesters, devs, and negotiators, are spread throughout various cybercrime operations, but they are still part of the Conti syndicate and fall under the same leadership. This helps them avoid law enforcement while still carrying out the same cyberattacks as they did under the Conti brand.

Conti was considered one of the most expensive and dangerous types of ransomware ever created, with over $150 million of ransom payments collected during its two-year stint. The U.S. government offers a substantial reward of up to $15 million for help in identifying the individuals involved with Conti, especially those in leadership roles.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
NVIDIA’s new AI can detect deepfake videos in just 22 milliseconds
NVIDIA has a new AI tool that can tell fake videos from real ones in milliseconds
Nvidia logo

As generative AI becomes increasingly capable of producing videos that are nearly indistinguishable from real footage, the race is no longer just about creating synthetic media. It's about detecting it before it spreads.

At SIGGRAPH 2026, NVIDIA unveiled Synthetic Video Detector, a new AI-powered verification tool designed to identify AI-generated videos with remarkable speed and accuracy. Rather than replacing traditional fact-checking or forensic analysis, the company says the technology is intended to give newsrooms, broadcasters and enterprises another layer of confidence before synthetic videos enter the public domain.

Read more
Dell XPS 14 (2026) Review: Dell’s classic Windows laptop returns, and it’s hard to put down
The icon returns, and shows why it's still relevant
Dell XPS 14 Review: Featured

Quick take

Dell’s XPS line has always carried a certain weight. It is one of those Windows laptop families that people recognize even if they don’t follow laptops too closely. Clean design built with premium materials, sharp displays, and high-end hardware. The Dell XPS 14 DA14260 continues that legacy. 

Read more
Samsung’s secret AI chip could finally cool down Exynos phones
Samsung's GAIA AI chip is landing in laptops first, but its shared DNA with Exynos hints at a real fix for phones down the line.
Samsung Exynos chip illustration.

If you've ever owned an Exynos-powered Galaxy phone, you already know the drill: heavy tasks like capturing back-to-back pictures or photos for a while, heavy gaming, or rendering videos turn your device into a hand warmer. 

In such a situation, the battery bar drops faster than usual as well. Turns out, Samsung might be working on the fix, and it's coming in a way nobody expected.

Read more