Researchers have revealed the tactics and procedures of the new hacking group “Karakurt.” They monitored the recent cyberattacks carried out by the group and published the results of their investigation.

The hacking group calls itself “Karakurt” and is a financially motivated threat actor that has stepped up cyberattacks in the third quarter of 2021.
The first signs of activity by the Karakurt group were detected in June 2021, with the registration of two domains and the creation of a Twitter handle.
See also: Hacking group XE Group steals thousands of credit cards every day

Hackers focus almost exclusively on data extraction and extortion and do not use ransomware to lock their victims' files.
The report on Karakurt comes from Accenture Security researchers, who were able to track the group's tactics, toolset, and intrusion techniques "live off the land.".
The group claims to have compromised more than 40 victims between September and November 2021 and has published downloadable packages of stolen files on its websites.
Approximately 95% of these victims are based in North America, while the rest are European entities. The Karakurt group does not focus on a specific industry, so the victims appear to be random.
See also: Russian hacking group Nobelium targets French organizations
Entry, escalation and exfiltration
Hackers use VPN credentials to gain initial access to a victim's network, which they have either purchased from vendors or obtained through phishing.
Persistence is confirmed by the dropping of the widely used remote access tool Cobalt Strike, although, in recent attacks, Karakurt has used AnyDesk.
AnyDesk is becoming increasingly popular among threat actors, such as the Conti ransomware.
The hacker then steals additional credentials belonging to administrators using Mimikatz and uses them for undetectable privilege escalation
To extract the data, Karakurt uses 7zip and WinZip to compress the files and then sends everything to Mega.io via Rclone or FileZilla.
While these attacks seem less damaging compared to ransomware infections that encrypt data and wipe backups, they can be quite damaging.
The threat of publishing stolen files can bring a company to its knees.

For this reason, new hacking groups, such as SnapMC, focus exclusively on data extraction and extortion as a threat model.
However, paying a ransom does not guarantee that the threat actors will delete the stolen data or that they will not sell it to others, so it is never wise to pay a ransom to prevent a data breach.
See also: Nobelium hacking group uses new Ceeloader malware
Instead, organizations should focus on defense, prevention, and detection measures to keep these threats out of their networks.
Information source: bleepingcomputer.com
