Conti_locker.7z ⇒ 〈VERIFIED〉

The group not only encrypted data but exfiltrated it, threatening to publish it on their "Conti News" site if the ransom was not paid.

Appends a specific, often randomized, extension to encrypted files. conti_locker.7z

Frequently via stolen credentials (via TrickBot/Pony) or phishing. The group not only encrypted data but exfiltrated