Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primarily targeting US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance. Known victims: 7

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Chort, a double-extortion ransomware group emerging in October 2024, primarily targets US education and government sectors. Known for its aggressive tactics including data theft and encryption demands, Chort has victimized entities like the City of Sheboygan and Kuwait's Ministry of Finance, indicating a global reach despite limited operational history.

Goals & Targeting

Chort's targeting strategy centers around sectors with accessible and sensitive data, such as education and government institutions. Their focus on these industries may stem from the higher likelihood of successful extorsion due to the critical nature of services disrupted. The US and Kuwait suggest a possible geographic focus or strategic interest in specific regions rich in financial or data resources. victims include municipalities and ministries, indicating a preference for targets with substantial recovery costs.

Enhanced Description

Chort, translating to 'Devil' in Russian, is a double-extortion ransomware group that surfaced in October 2024. They primarily target US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance. Their modus operandi involves encrypting data and demanding ransoms while threatening to release stolen information unless paid. This approach, combined with their relatively recent emergence, suggests a strategic focus on high-value targets where sensitive data is abundant. While specific attack techniques remain unclear, their operations highlight the growing prevalence of ransomware as a profit-driven tool for criminal groups.

Key Capabilities

  • Double-extortion ransomware deployment
  • Data exfiltration prior to encryption
  • Initial access methods

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Lateral Movement
Collection
Exfiltration
Impact

Software / Tooling

Double extortion ransomware
Cobalt Strike (hypothetical)

Campaigns & Victims

Chort has conducted operations since October 2024, targeting education and government sectors with notable cases in the US and Kuwait. The group's campaign patterns indicate a focus on high-impact targets, leveraging double extortion tactics to maximize profits. Their relatively short operational timeline suggests they are an emerging threat with limited but targeted campaigns.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Ransomware payload delivery via remote access

Recommended Actions

  • Implement comprehensive phishing awareness training
  • Monitor network traffic for suspicious activities
  • Regularly back up critical data offsite and verify integrity
  • Conduct incident response drills focusing on ransomware scenarios

Suggested Tags

Ransomware
Financial-gain
Education-sector
Government-sector

Confidence Assessment

Moderate confidence in Chort's profile, primarily based on double-extortion tactics and known victims. Limited visibility into specific TTPs or tools used leaves gaps in understanding their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Government Targeting
Financial-gain
Education-sector
Government-sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 17, 2024
Last Seen
Nov 22, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.