Karakurt is a Russia-linked cyber extortion operation associated with the broader Conti/TrickBot criminal ecosystem and active since at least 2020, with activity observed from mid-2021 onward. It is widely characterized as an extortion-focused ransomware brand that often emphasized data theft and coercive leak threats rather than relying solely on file encryption, making it part of the broader trend toward encryption-less or pure extortion operations. The group has been linked to former Conti members and has appeared alongside other successor or affiliated brands including Royal, TommyLeaks, SchoolBoys Ransomware, and Akira.
Karakurt primarily targeted organizations in North America and Europe, including businesses, government entities, and healthcare organizations. Reported tradecraft includes initial access through stolen VPN credentials, followed by use of common post-compromise tooling such as Cobalt Strike, remote administration software, credential theft utilities, scripting, and archive and transfer tools to move stolen data out of victim environments. Public reporting also links the operation to aggressive victim negotiation practices, short payment deadlines, and ransom demands ranging from relatively modest sums to multimillion-dollar amounts.
The operation is notable for its emphasis on exfiltration and extortion. Operators and affiliates analyzed stolen data, identified sensitive material, and used disclosure threats to pressure victims into paying. In documented cases tied to the broader organization using the Karakurt brand, extortion escalated to especially coercive tactics involving exposure or threatened sale of highly sensitive personal and healthcare information. Karakurt has also been associated with re-extortion behavior against previously compromised victims.
Law enforcement reporting has tied individuals linked to Karakurt to a structured, hierarchical Russian cybercrime organization connected to former Conti leadership. That broader organization used multiple brands over time, obscured operations through front companies, and caused substantial financial losses across dozens of victims worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In one case, attempts to exploit CVE-2020-1472, also known as Zerologon, were detected by security software. The actual environment was not vulnerable to Zerologon however indicating Karakurt may be attempting to exploit a number of vulnerabilities as part of their operation.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
During the time of Zolotarjovs’s active participation ... the organization stole data from over 54 companies ... Attacks during this period resulted in the theft and exposure of Social Security numbers, addresses, dates of birth, home addresses, healthcare information...
Trickbot is a cybercriminal group that has conducted ransomware campaigns across essential services including healthcare and banking.
When he failed in extracting a ransom from this victim, he urged coconspirators to be “DESTROYERS” and to leak or sell copies of these pediatric health records to sow fear among future victims. | During the time of Zolotarjovs’s active participation ... the organization stole data from over 54 companies ... Zolotarjovs was primarily responsible for escalating pressure on victims who initially resisted prompt payment of the organization’s ransom demands. Zolotarjovs analyzed stolen data, researched victim companies, and exploited his access to particularly sensitive and extremely personal information.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware/extortion-associated strain linked in the content to Stern’s transactions.
Named ransomware referenced only in a related-content link, without substantive discussion in the article.
A ransomware brand operated by the syndicate during the June 2021 to August 2023 period.
Karakurt is a cyber extortion/ransomware operation tied to former Conti members. It stole data from victim organizations, used that data for extortion, and in attacks leveraged VPN credentials for initial access, then tools such as Cobalt Strike, AnyDesk, Mimikatz, PowerShell, 7zip, WinZip, Rclone, and FileZilla to maintain access, escalate privileges, and exfiltrate data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.