Karakurt

Active
Karakurt is a pure data-extortion group (no encryption) assessed with high confidence to be the extortion arm of the Conti ransomware group, active from 2021, that steals data and threatens to auction or publish it unless ransoms ranging from $25,000 to $13 million are paid.
74 Victims
Dec 11, 2022 First Discovered
Sep 22, 2023 Last Discovered
1090 Days Inactive
0% Infostealer
1/3 Sites Online
Known Locations (3)
Magazine
3f7nxkjway3d223j27lyad7v5cgmyaifesycvmwq7i7cbs23lb6llryd.onion
Chat
omx5iqrdbsoitf3q4xexrqw5r5tfw7vp3vl3li3lfo7saabxazshnead.onion
karaleaks.com
karaleaks.com
Tools Used
CredentialTheft
Mimikatz
Exfiltration
FileZilla, MEGA, RClone
Networking
Ngrok
Offsec
Cobalt Strike
RMM-Tools
AnyDesk
Intelligence
Victims (74)

Detailed victim list temporarily unavailable

This group has 74 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.