Skip to content

KaraKurt

Karakurt is a Russia-linked cyber extortion operation active since at least June 2021 and closely associated with the Conti/TrickBot ecosystem.

Profile source: Mallory opens in a new tab

KaraKurt

Family profile

Karakurt is a Russia-linked cyber extortion operation active since at least June 2021 and closely associated with the Conti/TrickBot ecosystem. It is best known for extortion-only attacks that prioritize data theft and coercion over file encryption, using stolen information to pressure victims into paying under threat of public release or sale. Reporting and law-enforcement actions have linked Karakurt to former or overlapping Conti operators, shared infrastructure, shared financial flows, and follow-on monetization of intrusions where ransomware deployment was blocked or unsuccessful.

Karakurt primarily targeted organizations in North America and Europe, including businesses, healthcare entities, and government-related victims. The group has been associated with dozens of victims in a short period during late 2021 and with ransom demands ranging from relatively small sums to multimillion-dollar payments. Its operators have been noted for aggressive negotiation and re-extortion tactics, including renewed pressure against previously compromised victims.

Operationally, Karakurt has been associated with initial access via stolen VPN credentials and with post-compromise use of common intrusion tooling such as Cobalt Strike, AnyDesk, Mimikatz, PowerShell, Rclone, FileZilla, tunneling utilities, Metasploit, and Impacket. Observed behavior includes credential abuse, lateral movement, data staging, bulk exfiltration, and use of leak infrastructure to publish victim data when payment is refused. The group has shown particular interest in financially valuable stolen information.

Karakurt is widely characterized as an extortion-focused brand within the broader post-Conti criminal landscape rather than a distinct standalone malware family centered on encryption. It has also been referenced alongside later ransomware and extortion brands linked to former Conti personnel, including Royal and Akira. A U.S. criminal case against Deniss Zolotarjovs described a negotiator tied to the Karakurt-linked organization who analyzed stolen data and intensified pressure on victims, illustrating the group’s structured, professionalized extortion model.

Capabilities

  • Brute Force
  • Credential Theft
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Post Exploitation
  • Reconnaissance

Operational record

1
YARA rules
2
Ransom notes
3
Leak sites
1 available

Credential Theft

  • Mimikatz

Exfiltration

  • FileZilla
  • MEGA
  • RClone

Networking

  • Ngrok

Offsec

  • Cobalt Strike

RMM Tools

  • AnyDesk

Reported operators

Threat actors

1 named in public reporting
Stern

...Stern has transacted with addresses linked to strains like Quantum, Karakurt, Diavol, and Royal in 2022 following Conti’s demise.

Exploited software

Vulnerabilities linked to KaraKurt

1 CVEs

MITRE ATT&CK

KaraKurt in ATT&CK

3 distinct techniques

Reporting

Research mentioning KaraKurt

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Jul 14
Cyberscoop

US sanctions First VPN and administrator for supporting ransomware | CyberScoop

Jul 14
Chainalysis

“Stern” Ransomware Operator Sanctioned by EU

Jul 14
Cyber Security News

US Treasury Sanctions VPN Service that Helped Ransomware Actors to Attack Organizations

Jul 14
The Hacker News

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.