Karakurt — Ransomware Profile
Karakurt conducts data extortion without encrypting files, threatening to auction or publish stolen data. Believed to be affiliated with former Conti operators.Also tracked as
Karakurt Team, Karakurt Lair
Tools & malware
- 7zip Data compression
- AnyDesk Remote access
- Cobalt Strike Post-exploitation framework
- FileZilla File transfer / exfiltration
- Mega.nz Cloud storage for stolen data
- Mimikatz Credential theft
- Ngrok Tunneling / C2
- rclone Data exfiltration
Vendor research
- Karakurt Data Extortion Group (Alert AA22-152A) CISA
- The Karakurt Web: Threat Intel and Blockchain Analysis Arctic Wolf
- Karakurt revealed as data extortion arm of Conti cybercrime syndicate BleepingComputer
- Karakurt-Hacking-Team-CTI (IOC data obtained from Karakurt internal infrastructure) Infinitum IT
- Cyber extortion group Karakurt linked to Conti and Diavol ransomware groups SC Media