Ransomware Group intelligence
Monti
InactiveTrack Monti with 110 published victims and 2 known leak locations in a single intelligence view.
Overview
Monti is tracked by Breach House as a ransomware group with 110 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 2h ago | mblogci3rudehaagbryjznltdp33ojwzkq6hn2pckvjq33rycmzczpid.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 4s4lnfeujzo67fy2jebz2dxskez2gsqj2jeb35m75ktufxensdicqxad.onion |
Top Activity Sectors (15)
- Not identified 24
- Communication / Marketing 20
- Services 10
- Healthcare / Pharma 9
- Manufacturing / Engineering 8
- Education 7
- IT 6
- Finance / Legal / Insurance 6
- Transportation / Travel / Logistics 4
- Retail / E-commerce 4
- Public Sector 4
- Telecommunications 3
- Agriculture / Food 2
- Energy 2
- Construction / Real Estate 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Monti, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: monti uses PowerShell to execute malicious payloads and spread ransomware across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: monti modifies Registry Run Keys to establish persistence by executing ransomware on system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: monti disables or modifies security tools like antivirus software to evade detection during ransomware deployment.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: monti inserts junk code into binaries to evade static analysis and detection mechanisms.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: monti deletes Volume Shadow Copies and backup files to prevent recovery without paying the ransom.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: monti accesses LSASS memory to steal credentials for persistence and privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1049 System Network Connections Discovery Discovery
What they do: monti queries system network connections to identify active hosts and communication channels for exfiltration.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: monti performs network share discovery to identify accessible file shares for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: monti leverages SMB/Windows Admin Shares to move laterally within victim networks.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: monti encrypts victim files using strong encryption to achieve impact and demand ransom payments.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Tools Observed (10)
▼Software Monti has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
Discovery & enumeration
Exfiltration
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
bidon_readme.txt
All of your files are currently encrypted by BIDON strain. If you don't know who we are - just "Google it." As you already know, all of your data has been encrypted by our software. It cannot be recovered by any means without contacting our team directly. DON'T TRY TO RECOVER your data by yourselves. Any attempt to recover your data (including the usage of the additional recovery software) can damage your files. However, if you want to try - we recommend choosing the data of the lowest value. DON'T TRY TO IGNORE us. We've downloaded a pack of your internal data and are ready to publish it on our news website if you do not respond. So it will be better for both sides if you contact us as soon as possible. DON'T TRY TO CONTACT feds or any recovery companies. We have our informants in these structures, so any of your complaints will be immediately directed to us. So if you will hire any recovery company for negotiations or send requests to the police/FBI/investigators, we will consider this as a hostile intent and initiate the publication of whole compromised data immediately. To prove that we REALLY CAN get your data back - we offer you to decrypt two random files completely free of charge. You can contact our team directly for further instructions through our website : TOR VERSION : (you should download and install TOR browser first https://torproject.org) http://myosbja7hixkkjqihsjh6yvmqplz62gr3r4isctjjtu2vm5jg6hsv2ad.onion/chat/[snip]/ Also visit our blog (via Tor): http://mblogci3rudehaagbryjznltdp33ojwzkq6hn2pckvjq33rycmzczpid.onion/ YOU SHOULD BE AWARE! We will speak only with an authorized person. It can be the CEO, top management, etc. In case you are not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! Inform your supervisors and stay calm!
readme.txt
All of your files are currently encrypted by MONTI strain. If you don't know who we are - just "Google it." As you already know, all of your data has been encrypted by our software. It cannot be recovered by any means without contacting our team directly. DON'T TRY TO RECOVER your data by yourselves. Any attempt to recover your data (including the usage of the additional recovery software) can damage your files. However, if you want to try - we recommend choosing the data of the lowest value. DON'T TRY TO IGNORE us. We've downloaded a pack of your internal data and are ready to publish it on our news website if you do not respond. So it will be better for both sides if you contact us as soon as possible. DON'T TRY TO CONTACT feds or any recovery companies. We have our informants in these structures, so any of your complaints will be immediately directed to us. So if you will hire any recovery company for negotiations or send requests to the police/FBI/investigators, we will consider this as a hostile intent and initiate the publication of whole compromised data immediately. To prove that we REALLY CAN get your data back - we offer you to decrypt two random files completely free of charge. You can contact our team directly for further instructions through our website : TOR VERSION : (you should download and install TOR browser first https://torproject.org) http://monti5o7lvyrpyk26lqofnfvajtyqruwatlfaazgm3zskt3xiktudwid.onion/chat/[snip]/ Our blog : (also through TOR) http://mblogci3rudehaagbryjznltdp33ojwzkq6hn2pckvjq33rycmzczpid.onion YOU SHOULD BE AWARE! We will speak only with an authorized person. It can be the CEO, top management, etc. In case you are not such a person - DON'T CONTACT US! Your decisions and action can result in serious harm to your company! Inform your supervisors and stay calm!
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (110)
Search, filter and paginate the victim timeline for Monti. Showing 101–110 of 110.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ASL 1 - Avezzano Sulmona L'Aquila id6318 View details | Italy | Other | ||
|
asl1abruzzo.it Portale istituzionale dell'Azienda Sanitaria Locale 1 Avezzano Sulmona L'Aquila. |
|||||
| Ransomware | Control & Automation technology - LUX Automation id6317 View details | IT | |||
|
lux-automation.com For drive, regulation or control technology: LUX Automation is your expert when it comes to automation technology and process automation. |
|||||
| Ransomware | Weickert Industries id5861 View details | Other | |||
|
www.weickert.com |
|||||
| Ransomware | American Institute for Healthcare Quality id5775 View details | Healthcare / Pharma | |||
|
https://www.zoominfo.com/c/american-institute-for-healthcare-quality/359823076 |
|||||
| Ransomware | Donut Leaks id5774 View details | Other | |||
|
this gay rippers : Monti #ransomware team posted about how Dount Leaks stole 100K from them and did not 'fulfill the terms of the deal' 👀 |
|||||
| Ransomware | UnitedLex id5767 View details | Other | |||
|
www.unitedlex.com |
|||||
| Ransomware | Cambridge College id5711 View details | Education | |||
|
boston.cambridgecollege.edu |
|||||
| Ransomware | Regional Transportation Authority id5592 View details | Public Sector | |||
|
A government agency created by the State of Illinois to coordinate the Chicago region’s transit system https://rtachicago.org |
|||||
| Ransomware | Every one of you been a good customer this year id5080 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | test id4755 View details | Other | — | ||
|
No additional victim description available. |
|||||