Article
Conti Ransomware is the New Ryuk?
Arete Analysis

Summary
Arete’s Threat Intelligence team observed that Conti ransomware could be a rebrand of Ryuk ransomware, as both variants use similar tactics to deploy ransomware executables.
—————————————————————————
Background
Based on analysis of Conti ransomware, which was originally spotted in the wild in February of this year, the Arete Threat Intelligence team believes that this variant is being operated by the same group that conducted Ryuk ransomware attacks in the past. Digital forensics analysis of systems impacted by Conti ransomware revealed that it is generally being deployed by the attackers using the TrickBot banking trojan. Since early 2019, Ryuk ransomware operators exclusively used TrickBot trojan in their operations. In the 1st quarter of 2020, the number of Ryuk ransomware attacks significantly declined while the number of new Conti matters started to rise, which is a secondary indicator of a connection between both variants.
Conti Overview
Conti is a sophisticated ransomware variant that emerged in February 2020. Unlike most of its’ peers, Conti ransomware encrypts files on victims’ machines significantly faster by running 32 concurrent threads and utilizing all computing power that impacted systems have available. As a result of that, devices with multi-core CPUs get encrypted quicker. Conti has the capability to encrypt local hard drives, network shares and other devices on the local network. To encrypt the data, Conti uses the AES-256 encryption key, which is bundled with the RAS-4096 public encryption key (Note: this key is unique for each victim). Since the encryption key is unique for each victim, Conti operators cannot provide a decryption tool, which would work only on specific devices. The Conti decryption tool works on all encrypted systems within a victim’s networks.
Prior to the start of the encryption, Conti leverages Windows Restart Manager to disable security, backups and other applications that may keep files locked on the impacted systems. Then it deletes Shadow Volume copies to make it impossible to use built-in Windows volume backups to restore data after the encryption.
Once encryption completes, the .CONTI extension is added to all encrypted files and the ransom note, CONTI_README.txt, is placed in each folder. Each ransom note contains 2 email addresses to get in touch with the attackers, which are unique for each victim. This method is consistent with what Ryuk operators used in their attacks. Conti operators use a unique set of emails to identify each victim, so it does not matter if a victim responds from a corporate account or from a public email account – attackers still will know which victim they are communicating with. Just like Ryuk, Conti conducts research into information about their victims and sets ransom demands based on what they believe the victim can afford to pay.
Conti Ransom Note

Figure 1 - % of Data Exfiltration in Ryuk matters
It was uncommon for Ryuk to exfiltrate data from victims’ systems. Based on Arete analysis of previous matters, we only observed data exfiltration in 7% of cases. Unlike Ryuk, it appears that Conti ransomware operators decided to join the bandwagon of other 20+ variants that steal data from victims’ environments prior to the encryption. Conti also created a web site where they publish lists of their victims in attempt to improve their chances of getting paid. In the last few weeks, Conti stepped up their extortion attempts and, in some cases, called the owner/managers of companies directly, to inform them that they have been compromised and threaten them to release the stolen data if they don’t pay.
Security Recommendations
Below are a few recommendations that will help to protect your organization from Conti ransomware attacks:
Implement a sophisticated Endpoint Detection & Response (EDR) solution that will rely on behavior analysis, instead of just malware signatures, and have tamper-proof capabilities.
Keep your systems updated and disable SMBv1, to protect against Windows EternalBlue vulnerability, which is actively being used by the TrickBot banking trojan to propagate within a victims’ environment.
Block outbound traffic on your firewall for ports 447, 449 & 8082 (Note: along with 443 those ports are commonly used by TrickBot) and implement geo-blocking for foreign countries that you don’t have any employees in and don’t do business with.
Continuously educate your users on how to identify suspicious phishing emails and attachments.
Implement an off-site backup solution and test it regularly

Figure 2 - Screenshot of the Conti exfil site
Back to Blog Posts
Podcast
Blockchain Unmasked: The Role of Cryptocurrency in Cybercrime and Threat Intelligence
In this episode of Bytes of Insight, host Vinny Sakore sits down with John Morrissey, Arete’s Director of Cryptocurrency Operations and Sanctions Compliance, and Trenton Howard, Arete’s Lead Threat Intelligence Consultant, to discuss cryptocurrency and blockchain technology. They explore the impact of cryptocurrency on both innovation and cybercrime, threat actors’ use of the blockchain for ransom payments, and Arete’s patent-pending Compliance and Sanctions Analysis Process.
Article
ClickFix Evolves in Server-Side Polymorphic Malware Delivery Campaigns
The ClickFix social engineering technique has significantly evolved from a relatively simple malware delivery mechanism into a highly sophisticated, evasive attack framework. Initially relying on straightforward PowerShell downloaders and disk-based payloads, the campaign now employs fileless execution, advanced obfuscation techniques, and server-side polymorphism to evade traditional security controls.
What’s Notable and Unique
ClickFix primarily relies on social engineering, as victims are presented with fake CAPTCHA verification pages that imitate trusted services such as Cloudflare or Google reCAPTCHA. Users are instructed to copy and execute a PowerShell command, believing they are completing a legitimate verification process. Instead, the command initiates the malware infection chain.
To bypass traditional security tools, threat actors transitioned to fileless techniques. Instead of downloading scripts directly to disk, newer variants execute malicious code entirely in memory. The most notable recent advancement in ClickFix is the adoption of server-side polymorphism. Unlike traditional malware that delivers a static payload, the threat actor's server dynamically generates unique payloads for each victim request. This approach undermines signature-based detection methods because each delivered payload appears unique, preventing defenders from relying solely on file hashes or static indicators.
The campaign was observed beginning around March 25, 2026, with a significant increase in activity thereafter, indicating that the techniques are proving effective against many organizations' defenses.
Analyst Comments
ClickFix social engineering campaigns continue to evolve in 2026, becoming more sophisticated and expanding across multiple operating systems. Organizations should focus on behavioral detection, browser isolation, endpoint monitoring, and user awareness training rather than relying solely on indicators such as hashes or blocklists. The campaign's use of fake CAPTCHA prompts also reinforces the importance of educating users never to execute commands from websites.
Sources
The Evolution of ClickFix: From Cleartext to Server Side Polymorphism
Article
Ransomware Trends & Data Insights: July 2026
INC Ransom was the most active threat group in July, while activity remained relatively distributed among multiple threat groups, with 19 unique groups observed throughout the month. Alongside INC Ransom, Qilin, Global Secret Group, Anubis, and DragonForce rounded out the five most active threat groups observed in July. Several emerging threat actors were also observed during the month, including Booba Team, Settra, and Global Secret Group.

Figure 1. Activity from the top 3 threat groups in July 2026
Throughout the month, analysts at Arete identified several trends behind the threat actors perpetrating cybercrime activities:
In July 2026, Global Secret Group emerged as a new threat actor, leveraging the leaked LockBit 3.0 (LockBit Black) source code. Although the group began operations in June 2026, it quickly accumulated a substantial number of victims on its data leak site (DLS). The group operates through TOR-based negotiation portals and qTox communications. Notably, its DLS provides step-by-step guidance on purchasing Bitcoin, including references to Coinbase and Binance, demonstrating a streamlined, victim-focused extortion process designed to simplify ransom payments.
Similar to Fulcrumsec, the recently emerged Settra ransomware group appears to leverage AI-driven analysis of stolen data, publishing detailed and highly structured victim reports on its DLS. Additionally, a potential EDR-disabling tool, edr_blind.exe, was identified in multiple cases, suggesting a focus on defense-evasion capabilities.
With the continuation of the FortiBleed campaign, researchers have now identified compromised FortiGate credentials being leveraged by both the INC and Lynx ransomware operations. Analysis revealed direct operational links between the groups, including shared ransomware infrastructure and overlap between FortiBleed victims and ransomware targets. The operators are also incorporating AI to enhance various stages of the attack lifecycle and increase operational efficiency and scale. Notably, Arete also observed an INC ransomware intrusion leveraging FortiBleed-derived access in July, reinforcing the campaign's role as a precursor to ransomware deployment.
Sources
Arete Internal
Podcast
Cyber Campfire: June Threat Trends & Insights
In this episode of Arete’s Cyber Campfire podcast, our Threat Intelligence Team discusses trends, statistics, and emerging threat actors from June 2026. Tune in for firsthand insights on today’s threat landscape that can enhance your approach to cyber risk.



