dharma

Aliases: Arena, Crysis, Wadhrama, ncov

First seen
2016-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-22 04:03:53
Profile updated
2026-07-07 12:41:44

Targeted industries: education-and-nonprofits energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing professional-services retail-and-hospitality technology-and-telecommunications transportation-and-logistics

Context

Dharma is a prolific ransomware family active since at least 2016, evolving from the earlier CrySiS ransomware. It operates under a Ransomware-as-a-Service (RaaS) model, allowing affiliates to deploy customized builds with their own contact emails and extensions. Dharma typically appends encrypted files with patterns like .id-[victimID].[email].dharma or other campaign-specific suffixes. Initial access is often gained through exposed Remote Desktop Protocol (RDP) services secured with weak or stolen credentials, sometimes combined with brute-force attacks. The malware encrypts files using AES with RSA to secure the keys and drops ransom notes in text files and pop-up windows. Numerous variants have emerged over time, each linked to different affiliates, making attribution difficult.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Dharma (yara-rule)
  • MALPEDIA_Win_Dharma_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • services.google.com — Google Fog Of War Research Report (report)
  • CrowdStrike — Ransomware Preparedness A Call To Action (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • huntandhackett.com — Advanced Ip Scanner The Preferred Scanner In The Apt Toolbox (report)
  • paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
  • ESET — Eset Threat Report Q22020 (report)
  • youtube.com — Watch (report)
  • nakedsecurity.sophos.com — The Rise Of Targeted Ransomware (report)
  • bleepingcomputer.com — The Week In Ransomware April 1St 2022 I Can Fight With A Keyboard (report)
  • Kaspersky — 104452 (report)
  • ransomlook.io — Dharma (report)
  • bleepingcomputer.com — Dharma Ransomware Switches To The Aes 256 Encryption Algorithm (report)
  • CISA — Aa23 259A (report)
  • Trend Micro — Dharma Ransomware Continues To Target Servers Via Open Rdp Ports (report)
  • mandiant.widen.net — M Trends 2023 (report)
  • trellix.com — Phobos Stealthy Ransomware That Operated Under The Radar Until Now (report)
  • Trend Micro — Negasteal Uses Hastebin For Fileless Delivery Of Crysis Ransomware (report)
  • justice.gov — Download (report)
  • europol.europa.eu — 12 Targeted For Involvement In Ransomware Attacks Against Critical Infrastructure (report)
  • npu.gov.ua — Kiberpolicziya Vikrila Transnaczionalne Zlochinne Ugrupovannya U Nanesenni Inozemnim Kompaniyam 120 Miljoniv Dolariv Zbitkiv (report)

External references