ZeroHour
CyberScooppublished ()ingested @AJVicens

U.S. cybersecurity officials issue notice on Karakurt extortion group

criticalRansomware exploited in the wildimportance 60
Full article916 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The suspected Conti ransomware group spinoff employs a variety of attack methods, the notice warns.

White karakurt spider on a flower of white petals of a chamomile flower (Getty Images)

A trio of U.S. government agencies on Wednesday issued an advisory with technical details related to the Karakurt data extortion gang, warning that the group has “employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation.”

Karakurt — also known as the Karakurt Team or Karakurt Lair — doesn’t destroy or encrypt victim files. Instead, the group steals data and threatens to publish it, with known ransom demands ranging between $25,000 and $13 million in bitcoin, according to the notice published jointly by the FBI, the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), the Treasury Department and the Treasury Department-run Financial Crimes Enforcement Network.

Karakurt is part of the Conti ransomware group, multiple independent cybersecurity researchers reported in April.

Wednesday’s notice does not reference Conti, but notes that Karakurt has extorted victims previously attacked with other ransomware variants, or at the same time the victims were under attack by other actors.

Conti has made international headlines of late after attacking more than two dozen Costa Rican government agencies beginning April 17. Costa Rican President Rodrigo Chaves declared a national emergency May 8 as a result of the attacks, and the U.S. State Department announced a $10 million reward for information leading to the identification and/or location of anybody holding a “key leadership position” within Conti.

Conti, among the most prolific and visible ransomware variants dating back to its first detection in December 2019, is in the process of shutting down, according to cybersecurity firm AdvIntel. The group’s public support of the Russian invasion of Ukraine made it difficult for the group to collect ransom payments as it had before.

While the group’s public data leak site remains operational, it’s back-end infrastructure was dismantled as of May 19 and its main operators and affiliates have split into various groups, including Karakurt.

Brett Callow, a threat analyst at cybersecurity firm Emsisoft, told CyberScoop Thursday that Karakurt’s leak site has been offline for several weeks, and he’s not aware of any recent Karakurt activity. Wednesday’s notice said the group maintains a website with “several terabytes” of purported victim data belonging to victims across North America and Europe, along with “press releases” naming victims who hadn’t paid.

The notice includes a dark web address that links to what appears to be Karakurt’s live “chat” website.

Callow said “it’s not clear whether CISA’s alert was due to concern that the Karakurt operation may be ramped up as the Conti operation is wound down.”

It wouldn’t be suprising to see an uptick in Karakurt activity, he added: “The Conti brand appears to be dead, and the actors behind it will be looking to spin up other operations. In fact, that’s almost certainly been in progress for some time.”

A CISA spokesperson told CyberScoop that “Karakurt continues to be an active threat actor attributed to tens of millions of dollars in losses across four continents,” and that a “significant number of US victims continue to report intrusions attributed to Karakurt.” The advisory’s information and security recommendations “will not only help to prevent and mitigate Karakurt extortion events, but also protect against a broad range of malicious cyber activity.”

Updated, 6/3/22: To include CISA’s statement on the timing of the advisory.

More Scoops

McKesson office building in San Francisco. California. (Getty Images)

McKesson copes with fallout from data theft extortion attack

The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility.

Programmable Logic Controller PLC System in Industrial Cabinet – stock photo, Ivan Shevchenko, Getty Images

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

A view of Medusa sculpture at Temple of Apollo ruins which stands as one of the best-preserved ancient temples of the classical era, as it draws attention with its magnificent architecture and mythological significance in Didim district of Aydin, Turkiye on October 15, 2025. (Photo by Sidar Can Eren/Anadolu via Getty Images)

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/karakurt-extortion-cisa-advisory-conti-ransomware/