Karakurt is a financially motivated, Russia-linked data-extortion and ransomware operation active since at least June 2021. It is closely associated with the Conti cybercrime ecosystem and has been assessed as a Conti-linked operation used to monetize intrusions where data is stolen, including cases in which ransomware encryption is not deployed or does not succeed. The operation steals victim data and demands payment under threat of public disclosure, using extortion-only tactics as well as activity associated with broader ransomware campaigns.
Karakurt activity has primarily affected organizations in North America, with additional victims in Europe. Reported targets include businesses, government entities, and healthcare providers. Operators have used compromised VPN credentials for initial access, followed by tooling including Cobalt Strike, AnyDesk, Mimikatz, PowerShell, Impacket, Metasploit, and tunneling or proxy utilities to conduct post-exploitation, credential access, network pivoting, and lateral movement. Stolen data is collected and transferred through common archiving and file-transfer tools before being used to pressure victims during negotiations.
Karakurt has been linked to Conti infrastructure, financial flows, personnel, and re-extortion activity against organizations previously compromised by Conti. U.S. authorities have also identified Karakurt as one of several brands used by a Russia-based ransomware organization associated with former Conti leaders. Deniss Zolotarjovs, a negotiator associated with this organization, was convicted in the United States for participating in extortion and money-laundering conspiracies. Karakurt ransom demands reportedly ranged from tens of thousands to millions of dollars in cryptocurrency.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In one case, attempts to exploit CVE-2020-1472, also known as Zerologon, were detected by security software. The actual environment was not vulnerable to Zerologon however indicating Karakurt may be attempting to exploit a number of vulnerabilities as part of their operation.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
During the time of Zolotarjovs’s active participation ... the organization stole data from over 54 companies ... Attacks during this period resulted in the theft and exposure of Social Security numbers, addresses, dates of birth, home addresses, healthcare information...
Trickbot is a cybercriminal group that has conducted ransomware campaigns across essential services including healthcare and banking.
When he failed in extracting a ransom from this victim, he urged coconspirators to be “DESTROYERS” and to leak or sell copies of these pediatric health records to sow fear among future victims. | During the time of Zolotarjovs’s active participation ... the organization stole data from over 54 companies ... Zolotarjovs was primarily responsible for escalating pressure on victims who initially resisted prompt payment of the organization’s ransom demands. Zolotarjovs analyzed stolen data, researched victim companies, and exploited his access to particularly sensitive and extremely personal information.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware operation mentioned only in comparison to a separate sentencing case; the content identifies a ransomware negotiator but provides no additional technical details.
A ransomware/extortion-associated strain linked in the content to Stern’s transactions.
Named ransomware referenced only in a related-content link, without substantive discussion in the article.
A ransomware brand operated by the syndicate during the June 2021 to August 2023 period.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.