logo

The Karakurt Web: Threat Intel and Blockchain Analysis

ID: 66fa2f69-bd8c-5198-b072-75ea064922b9

STIX ID: report--66fa2f69-bd8c-5198-b072-75ea064922b9

Feed Name: Arctic Wolf Blog

Threat Score
80/100

Date Published: 2022-04-15

Date Updated: 2026-04-26

...
...

This report presents forensic and blockchain evidence linking the Karakurt data‑theft extortion group to Conti and Diavol ransomware operations: investigators observed shared TTPs (Fortinet SSL VPN compromise, Cobalt Strike backdoor, WinSCP exfiltration and a recurring "file-tree.txt" artifact), identical attacker hostnames, and cryptocurrency flows showing shared wallet hosting and direct transfers between Karakurt and Conti addresses; Karakurt conducts exfiltration-only extortion across multiple industries and countries and retains copies of victim data even after payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.