Conti / Wizard Spider
The crew behind Conti, Ryuk and the Trickbot botnet. Formally disbanded in 2022 but seeded Black Basta, Royal/BlackSuit and Akira. Operators were sanctioned via the Trickbot designations.
Claimed victims
333
Top region
—
Top sector
—
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2022-06-07 | Alliance Steel | — | — |
| 2022-05-25 | LCRD | — | — |
| 2022-05-25 | The Contact Company | — | — |
| 2022-05-24 | Central Restaurant Products | — | — |
| 2022-05-24 | Schaumburg Park District | — | — |
| 2022-05-24 | RateGain | — | — |
| 2022-05-23 | Imenco AS | — | — |
| 2022-05-23 | Concepts in Millwork | — | — |
| 2022-05-23 | Eurofred | — | — |
| 2022-05-23 | Agile Sourcing Partners | — | — |
Suspected origin
Russia — Russian-speaking; leaked internal chats. Attribution reflects open-source consensus, not certainty.
Suspected affiliates & lineage
Ransomware crews share affiliates, tooling and operators; brands fall and reappear under new names. Related to:
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.