Also known as: Karakurt Lair
Karakurt is a pure data-extortion group (no encryption) assessed with high confidence to be the extortion arm of the Conti ransomware group, active from 2021, that steals data and threatens to auction or publish it unless ransoms ranging from $25,000 to $13 million are paid. Known victims: 74 2 ransom note(s) on file
Objectives
Executive Summary
Karakurt is a medium-sophistication criminal threat actor assessed with high confidence as the extortion wing of the Conti ransomware group. Specializing in data theft and non-encryption-based extortion, Karakurt operates since December 2022, targeting businesses globally to extract ransoms ranging from $25,000 to $13 million through data auction or publication threats.
Goals & Targeting
Karakurt's primary objectives are organizational gain through financial extortion using stolen data. They target a broad array of industries where(data exposure could severely damage business reputation or cause financial loss. Their global targeting scope suggests they seek high-value datasets from businesses across various sectors, exploiting the fear of data exposure topressure organisations into paying ransoms.
Enhanced Description
Karakurt primarily engages in data-extortion activities without deploying encryption, distinguishing it from traditional ransomware operations. This group窃取 victims' sensitive data and threatens exposure unless substantial ransoms are paid. Linked with the Conti ransomware group since at least 2021 as its extortion arm, Karakurt has targeted a wide range of business sectors globally. Their operational timeline spans from 2022-12-11 to 2023-09-22, with known victims totaling 74 and associated ransom notes on file.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
Karakurt has conducted numerous campaigns targeting businesses globally, leveraging the infrastructure and reputation of the Conti ransomware group. Their operations demonstrate a focus on maximizing financial gain through data theft, with ransoms ranging from low to high values depending on the victim's perceived ability to pay.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Karakurt's association with Conti is high, based on the description provided. However, gaps exist regarding specific tactics, techniques, and tools used, which limits detailed threat intelligence analysis.
No techniques linked yet.
No tools linked yet.
Conti Ransomware
Imported from MISP event #255 (0319b483-5973-4932-91ea-5a44c2975b24).
May 16, 2021
TLP:CLEARNo observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics