Worked example · 2021-20
Karakurt encryption-free data-theft extortion operation — 2021–2025
Summary
Karakurt emerged in mid-2021 as a data-extortion sub-team within the broader Conti/Wizard Spider operator-cohort substrate. The cluster's name — Karakurt, the Central Asian black-widow spider — and its black-and-red leak-site visual identity ("Karakurt Lair") have been consistent across the cluster's 2021–present operating window.
The cluster's signature operational pattern: (1) initial access via exploitation of public-facing vulnerabilities, spear-phishing, and purchased network access; (2) lateral movement and data exfiltration to attacker-controlled infrastructure; (3) victim notification and negotiation via the Karakurt Lair Tor leak site, with cryptocurrency-denominated extortion payments demanded under threat of data disclosure; (4) no ransomware encryptor deployed — the extortion lever is exclusively the threat of leaked-data publication.
Karakurt survived the May 2022 Conti dissolution as a standalone operating brand, distinguishing it from Conti-successor brands that were catalysed (rather than merely pre-existing) by the ContiLeaks dispersal. The cluster's encryption-free model was subsequently adopted at scale by Cl0p (OAK-G14) from mid-2023 onward in the MOVEit, GoAnywhere, and Cleo data-theft campaigns — the Karakurt prototype became the dominant post-2023 data-extortion operational model.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2021-mid | Karakurt emerges as Conti-side-channel data-extortion sub-team; Karakurt Lair leak site goes live | (cluster emergence) |
| 2021–2022 | Karakurt operates within the Conti/Wizard Spider substrate; data-theft extortion operations against U.S. and European targets | T5.008 |
| 2022-05 | Conti dissolution; Karakurt survives as standalone operating brand | (organisational event) |
| 2023–2025 | Cl0p adopts the Karakurt prototype encryption-free model at scale (MOVEit, GoAnywhere, Cleo campaigns) | (model diffusion) |
| Continuing | Karakurt data-extortion operation remains active at v0.1 cutoff | (ongoing) |
Public references
- Mandiant / Microsoft / CrowdStrike / SentinelOne: multi-vendor Karakurt cluster tracking and TTP characterisation.
- Recorded Future: Karakurt Conti-side-channel lineage analysis.
- Chainalysis: Karakurt extortion-payment flow tracking and downstream laundering analysis.