dharma
Aliases: Arena, Crysis, Wadhrama, ncov
- First seen
- 2016-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:03:53
- Profile updated
- 2026-07-07 12:41:44
Targeted industries: education-and-nonprofits energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing professional-services retail-and-hospitality technology-and-telecommunications transportation-and-logistics
Context
Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It operates under a Ransomware-as-a-Service (RaaS) model, allowing affiliates to deploy customized builds with their own contact emails and extensions. Dharma typically appends encrypted files with patterns like .id-[victimID].[email].dharma or other campaign-specific suffixes. Initial access is often gained through exposed Remote Desktop Protocol (RDP) services secured with weak or stolen credentials, sometimes combined with brute-force attacks. The malware encrypts files using AES with RSA to secure the keys and drops ransom notes in text files and pop-up windows. Numerous variants have emerged over time, each linked to different affiliates, making attribution difficult.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Dharma (yara-rule)
- MALPEDIA_Win_Dharma_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- services.google.com — Google Fog Of War Research Report (report)
- CrowdStrike — Ransomware Preparedness A Call To Action (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- huntandhackett.com — Advanced Ip Scanner The Preferred Scanner In The Apt Toolbox (report)
- paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
- ESET — Eset Threat Report Q22020 (report)
- youtube.com — Watch (report)
- nakedsecurity.sophos.com — The Rise Of Targeted Ransomware (report)
- bleepingcomputer.com — The Week In Ransomware April 1St 2022 I Can Fight With A Keyboard (report)
- Kaspersky — 104452 (report)
- ransomlook.io — Dharma (report)
- bleepingcomputer.com — Dharma Ransomware Switches To The Aes 256 Encryption Algorithm (report)
- CISA — Aa23 259A (report)
- Trend Micro — Dharma Ransomware Continues To Target Servers Via Open Rdp Ports (report)
- mandiant.widen.net — M Trends 2023 (report)
- trellix.com — Phobos Stealthy Ransomware That Operated Under The Radar Until Now (report)
- Trend Micro — Negasteal Uses Hastebin For Fileless Delivery Of Crysis Ransomware (report)
- justice.gov — Download (report)
- europol.europa.eu — 12 Targeted For Involvement In Ransomware Attacks Against Critical Infrastructure (report)
- npu.gov.ua — Kiberpolicziya Vikrila Transnaczionalne Zlochinne Ugrupovannya U Nanesenni Inozemnim Kompaniyam 120 Miljoniv Dolariv Zbitkiv (report)