chort

First seen
2024-10-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:54:15

Targeted industries: education-and-nonprofits

Targeted regions: country_code:us country_code:kw

Context

Chort is a relatively new data-extortion ransomware group that surfaced in late 2024, with confirmed activity beginning in October–November 2024. It operates under a double-extortion model—exfiltrating sensitive data before encrypting systems—and organizes victims via a Tor-hosted data leak site (DLS). The group has targeted organizations in the U.S. education sector (including schools and nonprofits) and in Kuwait's agriculture sector, among others. Technical behaviors include execution via PowerShell and removal of shadow copies to disrupt recovery. The group's approach emphasizes public pressure through data exposure rather than technical innovation.

Reports & references

  • ransomlook.io — Chort (report)
  • cyjax.com — The Devil And The Termite Data Leak Sites Emerge For Chort And Termite Extortion Groups (report)
  • watchguard.com — Chort (report)
  • therecord.media — Ransomware Sheboygan Breach Notice (report)

External references