Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Monti is a financially motivated ransomware operation first observed in June 2022 that became notorious for closely imitating the Conti ransomware gang, reusing Conti's leaked source code, TTPs, and a Conti-style data-leak site. Early Windows encryptors were ~99% similar to Conti binaries, but in 2023 the group shipped a substantially rewritten Linux/ESXi encryptor with far less Conti overlap. After a two-month pause in mid-2023 it relaunched with the new variant, and public tracking shows its last observed leak-site activity around May 2025, after which it went dormant.
Monti emerged in June 2022 in the aftermath of the Conti leaks. In March 2022 a Ukrainian member of Conti, angered by the gang's public support for Russia's invasion of Ukraine, leaked roughly 393 internal files including chat logs, training material, real-world identities, and the ransomware source code and builder. Monti capitalized on this dump: its early Windows encryptor was built from the leaked Conti source and, per Trend Micro, showed as much as 99% binary similarity to Conti via BinDiff. Beyond the code, Monti mirrored Conti's tradecraft and even its extortion infrastructure, running a Conti-style data-leak site — the imitation was blatant enough that BlackBerry described the group as a 'real-world doppelganger.'
In September 2022, BlackBerry's Incident Response team documented a Monti intrusion in which the actor exploited the Log4Shell vulnerability (CVE-2021-44228) against a client's internet-facing VMware Horizon virtualization infrastructure, then moved laterally and deployed the encryptor. BlackBerry assessed the actors chose overt Conti emulation precisely because Conti's internal playbooks, chat logs, and source were all public, lowering the barrier to replicating a mature operation.
In 2023 Monti diverged from its clone origins. After a roughly two-month operational break, it relaunched in August 2023 with a new Linux encryptor targeting VMware ESXi servers (Trend Micro detection Ransom.Linux.MONTI.THGOCBC). This variant was markedly different from earlier builds: BinDiff showed only ~29% similarity to the old Conti-based version (versus the prior 99%), the encryption scheme changed from Salsa20 to AES-256-CTR via OpenSSL, and command-line handling was reworked (a new --whitelist parameter; removal of --size, --log, and --vmlist). Notably it added a '-type=soft' option to shut down ESXi guest VMs more quietly than the earlier '-type=hard' behavior, reducing the chance of immediate detection. The encryptor appends a 'MONTI' marker plus key-related bytes, uses full encryption for files under ~1.05MB and intermittent encryption for larger files, adds a .monti extension, and drops readme.txt ransom notes. Reported victims in the March-August 2023 window skewed toward legal, financial services, and healthcare organizations, and aggregated tracking (ransomware.live) records roughly 110 victims across ~20 countries over the group's lifetime, concentrated in the United States, Canada, and Germany, in professional services, healthcare, and manufacturing. Public trackers show the last observed activity around 8 May 2025, and the group has since been inactive for over a year — hence a 'dormant' status (no formal shutdown or law-enforcement takedown has been announced, so 'defunct' is not asserted).
+12 more relationships — see the relationships browser.
MENA relevance: MENA exposure is minimal and low-confidence — the only MENA-linked data point is a single United Arab Emirates victim (a law firm, listed as 'BBLAWFIRM') appearing on Monti's own data-leak site as aggregated by ransomware.live; this is an unverified leak-site/aggregator claim, not corroborated by independent vendor incident reporting, and the RaqibCTI 'UAE' country tag on this actor should be treated as UNVERIFIED rather than confirmed targeting.