HomeSecurityNew hacking group Karakurt focuses on data theft &...

New hacking group Karakurt focuses on data theft & extortion

Researchers have revealed the tactics and procedures of the new hacking group “Karakurt.” They monitored the recent cyberattacks carried out by the group and published the results of their investigation.

Karakurt

The hacking group calls itself “Karakurt” and is a financially motivated threat actor that has stepped up cyberattacks in the third quarter of 2021.

The first signs of activity by the Karakurt group were detected in June 2021, with the registration of two domains and the creation of a Twitter handle.

See also: Hacking group XE Group steals thousands of credit cards every day

New hacking group Karakurt focuses on data theft & extortion

Hackers focus almost exclusively on data extraction and extortion and do not use ransomware to lock their victims' files.

The report on Karakurt comes from Accenture Security researchers, who were able to track the group's tactics, toolset, and intrusion techniques "live off the land.".

The group claims to have compromised more than 40 victims between September and November 2021 and has published downloadable packages of stolen files on its websites.

Approximately 95% of these victims are based in North America, while the rest are European entities. The Karakurt group does not focus on a specific industry, so the victims appear to be random.

See also: Russian hacking group Nobelium targets French organizations

Entry, escalation and exfiltration

Hackers use VPN credentials to gain initial access to a victim's network, which they have either purchased from vendors or obtained through phishing.

Persistence is confirmed by the dropping of the widely used remote access tool Cobalt Strike, although, in recent attacks, Karakurt has used AnyDesk.

AnyDesk is becoming increasingly popular among threat actors, such as the Conti ransomware.

The hacker then steals additional credentials belonging to administrators using Mimikatz and uses them for undetectable privilege escalation

To extract the data, Karakurt uses 7zip and WinZip to compress the files and then sends everything to Mega.io via Rclone or FileZilla.

While these attacks seem less damaging compared to ransomware infections that encrypt data and wipe backups, they can be quite damaging.

The threat of publishing stolen files can bring a company to its knees.

New hacking group Karakurt focuses on data theft & extortion

For this reason, new hacking groups, such as SnapMC, focus exclusively on data extraction and extortion as a threat model.

However, paying a ransom does not guarantee that the threat actors will delete the stolen data or that they will not sell it to others, so it is never wise to pay a ransom to prevent a data breach.

See also: Nobelium hacking group uses new Ceeloader malware

Instead, organizations should focus on defense, prevention, and detection measures to keep these threats out of their networks.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS