🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Global
KARAKURT

/actor/karakurt/  ·  0 intel reports

Year Established
2021
Attribution
Russia (Conti Group Affiliated)
Motivation
Financial
Modus Operandi (MO)
Data theft extortion without encryption, Conti/Diavol-linked infrastructure
Primary Aliases
Karakurt Team, Karakurt Hacking Team

Karakurt is a financially motivated threat actor assessed by multiple cybersecurity firms and US government agencies to be a subsidiary or affiliated extortion arm of the now-defunct Conti ransomware operation , one of the most prolific and damaging ransomware groups in history. Karakurt emerged as a distinct entity in late 2021, operating with a distinctive methodology that differentiates it from typical ransomware operators: the group focuses exclusively on data theft and extortion without deploying file-encrypting ransomware.

This "data theft only" approach offers several tactical advantages , it avoids triggering ransomware-specific detection tools, reduces the complexity of operations, and creates a different extortion dynamic where victims must weigh the reputational and regulatory consequences of data publication rather than the immediate operational impact of encrypted systems. Karakurt demands ransoms typically ranging from $25,000 to $13 million USD.

US government advisories from CISA, the FBI, and the US Treasury Department confirmed Karakurt's links to the Conti ecosystem, noting shared infrastructure, cryptocurrency wallets, and personnel with Conti and the Diavol ransomware operation. Following Conti's public implosion in mid-2022 , triggered by the leak of the group's internal communications after Conti expressed support for Russia's invasion of Ukraine , Karakurt continued operating as one of several successor entities.

Karakurt has targeted hundreds of organisations across healthcare, financial services, technology, and manufacturing sectors in North America and Europe. Their initial access methods include exploitation of known vulnerabilities and purchase of access from initial access brokers operating in criminal marketplaces, consistent with Conti's established operational practices.

Tactical Telemetry and Extortion Framework: In confirmed intrusions, Karakurt employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles