Karakurt is a Russian-linked, financially motivated data-extortion operation active since at least mid-2021. It is closely associated with the Conti cybercrime ecosystem and has been characterized as a Conti data-extortion arm or side operation, including for monetizing stolen data when ransomware encryption was unsuccessful or not deployed. U.S. court proceedings have described the broader organization as Russia-based and operating from St. Petersburg; Latvian national Deniss Zolotarjovs, known as Sforza_cesarini, was convicted in the United States for his role as a negotiator and money launderer for the operation. Karakurt primarily conducts encryption-less extortion: it steals victim data, demands cryptocurrency payments, and threatens to publish, sell, or auction the data through leak-site infrastructure. The group has also used victim harassment as leverage, including contacting employees, clients, and business partners and using sensitive personal or health information to intensify extortion. Its victims have included U.S. businesses, government entities, and healthcare providers; attacks attributed to the broader operation have disrupted emergency-dispatch services and exposed pediatric health information. Observed initial-access methods include abuse of valid or stolen VPN and remote-service credentials, phishing, exploitation of vulnerabilities, and access acquired from other cybercriminals or initial-access brokers. Post-compromise activity has included remote-account abuse, domain-trust and network reconnaissance, PowerShell-based password recovery, credential theft, policy modification, tunneling and proxy-based pivoting, SMB and RDP brute forcing, NTLM relay, and lateral movement. Karakurt operators have used Cobalt Strike, AnyDesk, Mimikatz, Rclone, FileZilla, and cloud-storage services in intrusion and exfiltration workflows. Karakurt is also referred to as Karakurt Team and Karakurt ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
32 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware groups that former Conti members reportedly splintered into after Conti shut down.
Cybercrime extortion group referenced in connection with a ransomware negotiator prosecuted by U.S. authorities.
Ransomware/extortion group accused of targeting more than 54 companies, including U.S. government entities, disrupting 911 dispatch systems, stealing children's health information, and using intimidation tied to alleged access to Russian government databases and law enforcement connections.
Financially motivated cyber extortion group involved in data theft and ransom negotiations, targeting dozens of organizations and extorting victims by threatening to leak stolen data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.