Aspire
Monti Ransomware Resurgence and Attack Overview
Pages
16
Time to read
18 mins
Publication
Language
English
Pages
16
Time to read
18 mins
Publication
Language
English
This report serves as a technical analysis of Monti ransomware, detailing its resurgence and recent attacks as of early 2025. Initially identified in June 2022, Monti ransomware gained attention for its resemblance to the defunct Conti ransomware, utilizing its leaked source code and tactics. After a period of inactivity in mid-2024, Monti resurfaced in January 2025, executing high-profile attacks on a variety of organizations. The report outlines the group’s evolution, noting changes in its tactics and techniques, particularly under new ownership. It highlights Monti's refined approach, including the use of advanced encryption methods, exploitation of vulnerabilities in public-facing applications, and reliance on Remote Monitoring and Management (RMM) tools for persistence. These developments suggest a more sophisticated operational framework, potentially linked to established ransomware-as-a-service (RaaS) models. The document further discusses the implications of these tactics for cybersecurity defenses and highlights the necessity for organizations to strengthen their defenses against such evolving threats.