U.S. charges Karakurt extortion gang’s “cold case” negotiator

Share:

A member of the Russian Karakurt ransomware group has been charged in the U.S. for money laundering, wire fraud, and extortion crimes.

An investigation from the FBI uncovered that 33-year old Deniss Zolotarjovs was a member of the Karakurt extortion operation that compromised company systems, stole data, and then demanded a ransom from the victims under the threat of leaking the data publicly or selling it to other cybercriminals.

The man is a Latvian national who lived in Moscow, Russia. In December 2023 he was arrested in Georgia, Eastern Europe, and was extradited to the U.S. earlier this month.

“According to court documents, Zolotarjovs is a member of a known cybercriminal organization that attacks computer systems of victims around the world,” the U.S. Department of Justice (DoJ) says in a press release.

“The group maintains a leaks and auction website that lists victim companies and offers stolen data for download.”

Karakurt ‘cold case’ negotiator

Although the DoJ did not name the ransomware operation, court documents show the Zolotarjovs’ connection to Karakurt, where he operated under the alias “Sforza_cesarini.”

Specifically, the FBI has linked Zolotarjovs with at least six cases of extortion impacting American organizations that occurred between August 2021 and November 2023.

In one of those cases, a victimized company paid Karakurt a ransom of more than $1.3 million. Another victim negotiated and paid $250,000 to the threat actor to avoid having its data leaked.

Zolotarjovs’s role was to negotiate so-called “cold case extortions” for the Karakurt operation, when communication after the attack had halted without a ransom being paid.

Zolotarjovs was identified through cryptocurrency tracing, communication analysis, and data obtained from search warrants executed on Rocket.Chat, linking him to the extortion and money laundering activities.

Karakurt is a cyber gang that launched operations in mid-2021, focusing entirely on data exfiltration and extortion without deploying any encryption tools in the attacks.

Between September to November 2021, the group had published 40 victims on its public leaks site, 95% of them being based in North America.

In April 2022, Karakurt was exposed as being a data extortion arm of Conti, a notorious cybercrime syndicate that has since been dismantled.

In June 2022, the U.S. authorities warned victims of Karakurt not to pay a ransom, noting that the hackers would most likely sell the data to others anyway, and not delete it as promised.

The next month, Karakurt launched a search tool on its leak site to make it easier to find specific data in the stolen datasets, effectively empowering the blackmail process and increasing the pressure on the victims.

Zolotarjovs is the first Karakurt member to be arrested and extradited to the U.S., and this success could lead to the identification and prosecution of more members in the future.

Regarding the potential sentence, each of the mentioned crimes incurs a maximum of 20 years in prison, plus a fine of up to $500,000 or twice the value of property involved in the transaction for conspiracy to commit money laundering.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:29 pm, Jul 5, 2025
weather icon 21°C
L: 20° | H: 22°
overcast clouds
Humidity: 74 %
Pressure: 1012 mb
Wind: 15 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:50 am
Sunset: 9:19 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
20° | 22°°C 0.2 mm 20% 12 mph 76 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 22°°C 1 mm 100% 10 mph 82 % 1010 mb 0 mm/h
Mon Jul 07 10:00 pm
weather icon
14° | 21°°C 0.2 mm 20% 13 mph 80 % 1015 mb 0 mm/h
Tue Jul 08 10:00 pm
weather icon
13° | 25°°C 0 mm 0% 10 mph 74 % 1020 mb 0 mm/h
Wed Jul 09 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 9 mph 50 % 1023 mb 0 mm/h
Today 7:00 pm
weather icon
20° | 21°°C 0 mm 0% 12 mph 76 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 21°°C 0.2 mm 20% 10 mph 74 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 8 mph 78 % 1010 mb 0 mm/h
Tomorrow 4:00 am
weather icon
17° | 17°°C 0 mm 0% 7 mph 82 % 1008 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 7 mph 79 % 1007 mb 0 mm/h
Tomorrow 10:00 am
weather icon
18° | 18°°C 0.03 mm 3% 8 mph 73 % 1006 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
19° | 19°°C 1 mm 100% 10 mph 77 % 1006 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
22° | 22°°C 0.97 mm 97% 10 mph 47 % 1005 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,752.26
0.53%
Ethereum(ETH)
€2,131.05
1.06%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.88
0.75%
Solana(SOL)
€124.93
0.51%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.138780
0.84%
Shiba Inu(SHIB)
€0.000009
2.03%
Pepe(PEPE)
€0.000008
2.30%
Scroll to Top