Cyber Threat Actor: Karakurt
| Actor Type | Location | Known Incidents |
Crime Syndicate
|
Russia
|
10 incidents |
|---|
Profile
Karakurt, also known as Karakurt Group or Karakurt Team, is a cyber extortion threat actor assessed to operate from Russia. The group specializes in data theft extortion, distinguishing itself by exfiltrating sensitive information without deploying ransomware to encrypt victim systems. Public reporting indicates Karakurt typically demands ransoms ranging from $25,000 to $13 million in Bitcoin, leveraging stolen data to pressure victims through harassing communications directed at employees, business partners, and clients. Their targeting spans multiple sectors, including healthcare (Petaluma Health Center, Medicalodges, Peachtree Orthopedics), education (Davenport Community Schools), local government (Municipality of Belen), religious institutions (Our Sunday Visitor), automotive (Nissan), and international NGOs (International Centre for Migration Policy Development). Geographic operations show a focus on North America and Europe, with victim selection based primarily on ease of access rather than industry-specific targeting.
Karakurt has established affiliations with the Conti ransomware group through shared infrastructure, cryptocurrency wallet transactions, and operational overlap. Security analysts and U.S. government agencies confirm Karakurt operates as a Conti offshoot, monetizing data stolen during intrusions where ransomware deployment was blocked. Notable campaigns include the 2022 breach of the International Centre for Migration Policy Development, involving theft of 375 GB of financial contracts, budgets, passports, and organizational correspondence. In 2023, the group claimed attacks on Nissan’s Australia and New Zealand divisions, potentially compromising customer personal data, and exfiltrated 130 GB of accounting, HR, and financial records from Catholic publisher Our Sunday Visitor. Additional operations against Davenport Community Schools and Costa Rica’s Belen municipality involved disputed claims of student data theft and temporary disruption of online services. Initial access frequently involves purchased stolen credentials or compromised network access from other threat actors, with incidents often discovered during concurrent ransomware attacks by different groups.
