Ransomware
Monti RansomwareMONTI
Attribution
Financially motivated ransomware operation; no confirmed nation-state or named-group attribution. Widely assessed by vendors (Trend Micro, BlackBerry) as an independent actor that deliberately imitated the Conti ransomware brand and reused Conti's leaked source code. The 'Monti' name itself is a play on 'Conti'.
Motivation
Financial gain via data-encryption extortion and double-extortion data-leak pressure.
Attribution confidence
medium
Sectors
Professional services
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE (Professional services sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.