We flagged this binary as Conti-style ransomware before checking threat intel.
All automated.
No unpacking. No signatures. Just behavior:
Threaded loader. AES/RSA encryption. Dynamic API calls.
It screamed “Conti” before we did.
Patterns > signatures.
delphoslabs.com/uploads/2b4e9a…