Conti Deploy Ransomware

Using the Jambi agent from the previous chain, delete the VSS shadow copies and then stage and execute ransomware on the affected hosts.

TTP Tuesday: Conti (Release 6)

Deploy Ransomware

Theme Overview

We're releasing the final instalment of our Conti ransomware theme with new TTPs focused on Windows ransomware deployment. To date, our Conti theme now contains the following kill-chains:

1. Recon and Initial Access
2. Local and Remote Discovery
3. Gain privileges and persist
4. Move to remote systems
5. Data collection and exfiltration
6. Deploy ransomware (Current Release)

Deploy Ransomware

Conti is considered Ransomware-as-a-Service (RaaS) and has an elaborate chain of events from initial access to execution of the ransomware. For this week, we are focusing on ransomware deployment techniques. The chain with resizing and deleting VSS shadow copies to make data recovery more difficult. Next, disarmed Conti malware (Conti samples modified such that they will not encrypt files when executed) is deployed on the host. Once the disarmed malware is deployed, Prelude’s GoRansom agent is staged and executed to simulate the Conti file encryption process. Finally, Conti ransom note variants are dropped on the victim hosts.

Watch a demonstration: Conti Deploy Ransomware

Staying up to date

Thanks for reading our latest TTP Tuesday release! Please subscribe and reach out with any feedback. We love to hear from our community!

There are several ways to follow us and learn more about Prelude and our team members:

Get our products

Download Prelude Operator:
See the latest kill chain and TTP Releases:
See our open-source repositories:

Join our community


Read, watch, and listen

Listen to our Podcast:
Read our blog:
Watch our live streams:
Watch our pre-recorded content:

Follow our team

David: privateducky
Alex: khyberspache
Kris: Xanthonus
Octavia: VVX7
Sam: wasupwithuman

Read more

Execute this chain

Download Operator (1.7.1)
Learn about Operator


Stage Conti readme
Stage Conti ransom note
Resize volume shadow copies
Download and execute Conti ransomware