Karakurt, also known as the Karakurt Team, Karakurt Hacking Team, and Karakurt Lair, is a Russian-linked, financially motivated cybercriminal group active since at least June 2021. It specializes in data theft and extortion without encrypting victim systems, threatening to publish or auction stolen information unless a ransom is paid. Its victims span multiple industries, including healthcare, with a strong concentration in North America and additional targeting in Europe. Karakurt has operated public and dark-web leak and auction sites. Its operational infrastructure, cryptocurrency flows, and reuse of access established by Conti connect it to the Conti syndicate, for which it served as a data-extortion arm, including monetizing intrusions when ransomware encryption was blocked. Karakurt obtains initial access through purchased credentials, criminal access brokers, cooperating intrusion groups, phishing, and exploitation of vulnerable internet-facing systems. Observed access methods include compromised VPN and RDP accounts and exploitation of Log4Shell, CVE-2021-44228. After compromise, operators use Cobalt Strike for network discovery and command and control, Mimikatz and PowerShell for credential theft, and AnyDesk for persistent remote access. Their tooling also supports privilege escalation, lateral movement, tunneling, and pivoting. Stolen information is commonly compressed with 7-Zip and transferred using FileZilla, FTP, rclone, and cloud storage services; individual thefts have exceeded one terabyte. Known ransom demands have ranged from $25,000 to $13 million in Bitcoin, typically with deadlines of approximately one week. Operators intensify pressure through repeated calls and emails to employees, clients, and business partners, often distributing samples of sensitive stolen information. Karakurt has also pursued renewed extortion against previously attacked organizations. Payment does not reliably ensure confidentiality or deletion of stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
51 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison to other ransomware-related prosecutions.
Mentioned only as a comparison to a separate ransomware-related sentencing involving a negotiator.
Named as one of the ransomware groups that former Conti members reportedly splintered into after Conti shut down.
Cybercrime extortion group referenced in connection with a ransomware negotiator prosecuted by U.S. authorities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.