Researchers and incident responders tied the Karakurt data extortion group to the Conti ransomware syndicate, concluding that both operated as parts of the same criminal enterprise. Infinitum IT reported access to Conti infrastructure, including a VPS holding more than 20TB of stolen victim data, and said it found technical links between a Conti operator and Karakurt systems through FileZilla connections and recovered SSH credentials. The findings indicate Karakurt was used in intrusions where attackers stole data but did not successfully deploy ransomware encryption.
Independent analysis from Arctic Wolf and Chainalysis supported the connection through incident response evidence and cryptocurrency tracing, pointing to shared infrastructure and financial flows between the two groups. The reporting said Karakurt hit more than 40 organizations over roughly two months in late 2021, reinforcing that the operation functioned as a dedicated extortion arm for Conti to monetize breaches through data theft and leak threats even when ransomware execution failed.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Infinitum IT released a CTI note publishing indicators of compromise and infrastructure allegedly tied to Karakurt, including command-and-control, data storage, and leak-site systems. The disclosure also described observed use of Ligolo-ng for SOCKS proxy pivoting and identified associated Ligolo-ng and Cobalt Strike infrastructure.
Infinitum IT reported evidence that the Conti ransomware syndicate and the Karakurt data extortion group were part of the same criminal operation, and Arctic Wolf independently supported the link. The public reporting also described Karakurt as a monetization path for attacks where data theft succeeded but ransomware encryption did not.
When the Conti leaks began, Infinitum IT said it gained access to multiple ProtonMail and Mega accounts used by a key Conti member. Those compromised accounts allegedly contained credentials and emails that enabled access to Conti infrastructure.
The reporting says Karakurt victimized more than 40 organizations over roughly two months in late 2021. The explicitly anchored period given is between September and November 2021.
The references state that Karakurt had been active since at least June 2021, focusing on stealing data and extorting victims by threatening to publish it rather than deploying encryption.
Chainalysis found that several Karakurt wallets sent cryptocurrency to wallets controlled by Conti and that Karakurt victim payment addresses were hosted by a Conti wallet. These blockchain findings supported the conclusion that the two operations shared management and financial flows.
Arctic Wolf reported that a client that had previously paid Conti was later breached by Karakurt through a Cobalt Strike backdoor left behind by Conti. The finding was part of joint research with Tetra Defense, Northwave, and Chainalysis across more than a dozen Karakurt incidents.
Infinitum IT reported obtaining SSH credentials for Karakurt's command-and-control server by exploiting an unpatched FileZilla vulnerability and recovering an SSH private key for the TOR leak site server. It said this allowed full compromise of Karakurt infrastructure, including access to the C2 server and attack tools.
Using credentials recovered from the compromised accounts, Infinitum IT said it accessed an internal Conti VPS server hosted by Inferno Solutions. The server reportedly contained more than 20TB of stolen victim data, including data tied to undisclosed victims.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcearcticwolf.com
Open sourcebleepingcomputer.com
Open sourceinfinitumit.com.tr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.