Karakurt
Also reported as Karakurt Lair and Mushy Scorpius.
Reports per quarter
Techniques seen in the last two years
- T1048 1 report
- T1078 1 report
- T1083 1 report
- T1133 1 report
- T1190 1 report
- T1219 1 report
- T1566 1 report
- T1566.001 1 report
- T1567.002 1 report
- T1589.001 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2015-2291 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2021-1879 KEV
- CVE-2021-207103
- CVE-2021-21166 KEV
- CVE-2021-21974
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
Show all 38 CVEs Show fewer
- CVE-2021-26857 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-27101 KEV ransomware
- CVE-2021-27102 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-33742 KEV
- CVE-2021-34523 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2022-29464 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-26169 KEV ransomware
- CVE-2024-27198 KEV ransomware
- CVE-2024-30051 KEV ransomware
- CVE-2024-4577 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackCat (Malware Family)
-
BazarBackdoor (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BazarBackdoor (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Conti (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HelloKitty (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
Show all 38 reports Show fewer
-
IcedID’s VNC Backdoors- Dark Cat, Anubis & Keyhole
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IcedID’s VNC Backdoors- Dark Cat, Anubis & Keyhole
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
Attack Graph Response to US CERT AA22-152A- Karakurt Data Extortion Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attack Graph Response to US CERT AA22-152A- Karakurt Data Extortion Group
-
Alert (AA22-152A)- Karakurt Data Extortion Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-152A)- Karakurt Data Extortion Group
-
DisCONTInued The End of Contis Brand Marks New Chapter For Cybercrime Landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DisCONTInued The End of Contis Brand Marks New Chapter For Cybercrime Landscape
-
Hydra with Three Heads- BlackByte & The Future of Ransomware Subsidiary Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hydra with Three Heads- BlackByte & The Future of Ransomware Subsidiary Groups
-
Enter KaraKurt- Data Extortion Arm of Prolific Ransomware Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Enter KaraKurt- Data Extortion Arm of Prolific Ransomware Group
-
Karakurt revealed as data extortion arm of Conti cybercrime syndicate
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Karakurt revealed as data extortion arm of Conti cybercrime syndicate
-
The Karakurt Web- Threat Intel and Blockchain Analysis Reveals Extension of Conti Business Model
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Karakurt Web- Threat Intel and Blockchain Analysis Reveals Extension of Conti Business Model
-
Karakurt Hacking Team Indicators of Compromise (IOC)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Karakurt Hacking Team Indicators of Compromise (IOC)
-
Detecting Karakurt – an extortion focused threat actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting Karakurt – an extortion focused threat actor
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Karakurt rises from its lair
Newest first. Details opens the report in Explore.