Credential Theft
- Mimikatz
Karakurt is a Russia-linked cyber extortion operation associated with the broader Conti/TrickBot criminal ecosystem and active since at least 2020, with activity observed from mid-2021 onward.
Profile source: Mallory opens in a new tabKaraKurt
Karakurt is a Russia-linked cyber extortion operation associated with the broader Conti/TrickBot criminal ecosystem and active since at least 2020, with activity observed from mid-2021 onward. It is widely characterized as an extortion-focused ransomware brand that often emphasized data theft and coercive leak threats rather than relying solely on file encryption, making it part of the broader trend toward encryption-less or pure extortion operations. The group has been linked to former Conti members and has appeared alongside other successor or affiliated brands including Royal, TommyLeaks, SchoolBoys Ransomware, and Akira.
Karakurt primarily targeted organizations in North America and Europe, including businesses, government entities, and healthcare organizations. Reported tradecraft includes initial access through stolen VPN credentials, followed by use of common post-compromise tooling such as Cobalt Strike, remote administration software, credential theft utilities, scripting, and archive and transfer tools to move stolen data out of victim environments. Public reporting also links the operation to aggressive victim negotiation practices, short payment deadlines, and ransom demands ranging from relatively modest sums to multimillion-dollar amounts.
The operation is notable for its emphasis on exfiltration and extortion. Operators and affiliates analyzed stolen data, identified sensitive material, and used disclosure threats to pressure victims into paying. In documented cases tied to the broader organization using the Karakurt brand, extortion escalated to especially coercive tactics involving exposure or threatened sale of highly sensitive personal and healthcare information. Karakurt has also been associated with re-extortion behavior against previously compromised victims.
Law enforcement reporting has tied individuals linked to Karakurt to a structured, hierarchical Russian cybercrime organization connected to former Conti leadership. That broader organization used multiple brands over time, obscured operations through front companies, and caused substantial financial losses across dozens of victims worldwide.
Reported operators
...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.
Exploited software
MITRE ATT&CK
Reporting
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.