Karakurt logo

Karakurt

0 incidentes 0 paises 0 sectores ransomware TR Ultimo: -
Aliases: Karakurt Team, Karakurt Lair
Ver en IntelTracker → APTTrail →
Karakurt is a financially motivated cybercriminal group that emerged in June 2021, distinguished by its exclusive focus on data exfiltration and extortion rather than deploying traditional file-encrypting ransomware. The group is assessed with high confidence to be of Russian origin, with strong operational ties to the now-defunct Conti ransomware group, potentially operating as a side business or a diversification strategy for Conti. Karakurt's primary motivation is financial gain through threatening to leak stolen sensitive data, often on dedicated leak and auction sites, to compel victims into paying a ransom. What sets Karakurt apart is their aggressive and often relentless harassment campaigns, contacting victims' employees, business partners, and clients with emails and phone calls—frequently including samples of the stolen data—to pressure organizations into paying. They are also known to exaggerate the extent and value of the data stolen to increase pressure on victims. The gro
Malware asociado
ESXiArgs, Storm-0978, Storm-0978
Tecnicas MITRE
T1082, T1595, T1195, T1587, T1055, T1114
CVEs relacionadas
CVE-2023-38831, CVE-2023-36884, CVE-2022-47966, CVE-2022-42475, CVE-2021-33764, CVE-2020-1472

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
ransomware
Pais origen
TR
Motivacion
-
Impacto
111
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesArmeniaAustriaAustraliaBelgiumBrazilBelarusCanadaSwitzerlandChile

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstruction