Karakurt is a Russia-linked cyber extortion operation active since at least June 2021 and closely associated with the Conti/TrickBot ecosystem. It is best known for extortion-only attacks that prioritize data theft and coercion over file encryption, using stolen information to pressure victims into paying under threat of public release or sale. Reporting and law-enforcement actions have linked Karakurt to former or overlapping Conti operators, shared infrastructure, shared financial flows, and follow-on monetization of intrusions where ransomware deployment was blocked or unsuccessful.
Karakurt primarily targeted organizations in North America and Europe, including businesses, healthcare entities, and government-related victims. The group has been associated with dozens of victims in a short period during late 2021 and with ransom demands ranging from relatively small sums to multimillion-dollar payments. Its operators have been noted for aggressive negotiation and re-extortion tactics, including renewed pressure against previously compromised victims.
Operationally, Karakurt has been associated with initial access via stolen VPN credentials and with post-compromise use of common intrusion tooling such as Cobalt Strike, AnyDesk, Mimikatz, PowerShell, Rclone, FileZilla, tunneling utilities, Metasploit, and Impacket. Observed behavior includes credential abuse, lateral movement, data staging, bulk exfiltration, and use of leak infrastructure to publish victim data when payment is refused. The group has shown particular interest in financially valuable stolen information.
Karakurt is widely characterized as an extortion-focused brand within the broader post-Conti criminal landscape rather than a distinct standalone malware family centered on encryption. It has also been referenced alongside later ransomware and extortion brands linked to former Conti personnel, including Royal and Akira. A U.S. criminal case against Deniss Zolotarjovs described a negotiator tied to the Karakurt-linked organization who analyzed stolen data and intensified pressure on victims, illustrating the group’s structured, professionalized extortion model.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In one case, attempts to exploit CVE-2020-1472, also known as Zerologon, were detected by security software. The actual environment was not vulnerable to Zerologon however indicating Karakurt may be attempting to exploit a number of vulnerabilities as part of their operation.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
During the time of Zolotarjovs’s active participation ... the organization stole data from over 54 companies ... Attacks during this period resulted in the theft and exposure of Social Security numbers, addresses, dates of birth, home addresses, healthcare information...
Trickbot is a cybercriminal group that has conducted ransomware campaigns across essential services including healthcare and banking.
When he failed in extracting a ransom from this victim, he urged coconspirators to be “DESTROYERS” and to leak or sell copies of these pediatric health records to sow fear among future victims. | During the time of Zolotarjovs’s active participation ... the organization stole data from over 54 companies ... Zolotarjovs was primarily responsible for escalating pressure on victims who initially resisted prompt payment of the organization’s ransom demands. Zolotarjovs analyzed stolen data, researched victim companies, and exploited his access to particularly sensitive and extremely personal information.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware/extortion-associated strain linked in the content to Stern’s transactions.
Named ransomware referenced only in a related-content link, without substantive discussion in the article.
A ransomware brand operated by the syndicate during the June 2021 to August 2023 period.
Karakurt is a cyber extortion/ransomware operation tied to former Conti members. It stole data from victim organizations, used that data for extortion, and in attacks leveraged VPN credentials for initial access, then tools such as Cobalt Strike, AnyDesk, Mimikatz, PowerShell, 7zip, WinZip, Rclone, and FileZilla to maintain access, escalate privileges, and exfiltrate data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.