The Karakurt Web: Threat Intel and Blockchain Analysis
ID: 66fa2f69-bd8c-5198-b072-75ea064922b9
STIX ID: report--66fa2f69-bd8c-5198-b072-75ea064922b9
Feed Name: Arctic Wolf Blog
This report presents forensic and blockchain evidence linking the Karakurt data‑theft extortion group to Conti and Diavol ransomware operations: investigators observed shared TTPs (Fortinet SSL VPN compromise, Cobalt Strike backdoor, WinSCP exfiltration and a recurring "file-tree.txt" artifact), identical attacker hostnames, and cryptocurrency flows showing shared wallet hosting and direct transfers between Karakurt and Conti addresses; Karakurt conducts exfiltration-only extortion across multiple industries and countries and retains copies of victim data even after payments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
