Karakurt

Aliases: Karakurt Lair

First seen
2021-06-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
Extortion
Profile updated
2026-07-07 12:04:11

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications retail-and-hospitality professional-services

Context

Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt victims have not reported encryption of compromised machines or files; rather, Karakurt actors have claimed to steal data and threatened to auction it off or release it to the public unless they receive payment of the demanded ransom. Known ransom demands have ranged from $25,000 to $13,000,000 in Bitcoin, with payment deadlines typically set to expire within a week of first contact with the victim.

Detection coverage

  • 154 YARA rules

Malware & tools used

Reports & references

  • CISA — Aa22 152A (report)
  • advintel.io — Enter Karakurt Data Extortion Arm Of Prolific Ransomware Group (report)
  • accenture.com — Karakurt Threat Mitigation (report)

External references