Chort is a double-extortion ransomware group (whose name means "Devil" in Russian) that emerged in October 2024, primarily targeting US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance. Known victims: 7
Objectives
Executive Summary
Chort, a double-extortion ransomware group emerging in October 2024, primarily targets US education and government sectors. Known for its aggressive tactics including data theft and encryption demands, Chort has victimized entities like the City of Sheboygan and Kuwait's Ministry of Finance, indicating a global reach despite limited operational history.
Goals & Targeting
Chort's targeting strategy centers around sectors with accessible and sensitive data, such as education and government institutions. Their focus on these industries may stem from the higher likelihood of successful extorsion due to the critical nature of services disrupted. The US and Kuwait suggest a possible geographic focus or strategic interest in specific regions rich in financial or data resources. victims include municipalities and ministries, indicating a preference for targets with substantial recovery costs.
Enhanced Description
Chort, translating to 'Devil' in Russian, is a double-extortion ransomware group that surfaced in October 2024. They primarily target US education and government sectors, with notable victims including the City of Sheboygan and Kuwait's Ministry of Finance. Their modus operandi involves encrypting data and demanding ransoms while threatening to release stolen information unless paid. This approach, combined with their relatively recent emergence, suggests a strategic focus on high-value targets where sensitive data is abundant. While specific attack techniques remain unclear, their operations highlight the growing prevalence of ransomware as a profit-driven tool for criminal groups.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
Chort has conducted operations since October 2024, targeting education and government sectors with notable cases in the US and Kuwait. The group's campaign patterns indicate a focus on high-impact targets, leveraging double extortion tactics to maximize profits. Their relatively short operational timeline suggests they are an emerging threat with limited but targeted campaigns.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in Chort's profile, primarily based on double-extortion tactics and known victims. Limited visibility into specific TTPs or tools used leaves gaps in understanding their full capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics