Dharma is a Windows file-encrypting ransomware family associated with the CrySiS lineage and active since 2016. It is distributed through a ransomware-as-a-service model in which criminal affiliates deploy the malware and demand payment for decryption. Dharma affects organizations worldwide, frequently targeting small and medium-sized businesses; documented victims also include healthcare organizations, breweries, and maritime ports. Phobos shares substantial technical and operational similarities with Dharma but is tracked as a distinct ransomware family.
Dharma intrusions commonly involve exposed Remote Desktop Protocol services accessed using weak, stolen, or leaked credentials, including credentials obtained through brute-force attacks. Operators typically deploy the ransomware manually after gaining access. Dharma has also been distributed through phishing and malicious spam. One campaign bundled the payload with a legitimate, unmodified ESET AV Remover installer to distract victims while encryption proceeded independently in the background.
The ransomware encrypts documents, databases, archives, media, source code, and other files on local drives and accessible network shares. Analyzed variants also detect newly available drives and encrypt their contents. Dharma uses AES for file encryption and protects encryption keys with RSA; cryptographic parameters differ between variants. It modifies encrypted filenames and presents ransom messages directing victims to contact the operators for decryption.
Dharma establishes persistence through Windows autorun entries and Startup folders. It stops database services and terminates applications that could prevent access to files, deletes Volume Shadow Copies to impair recovery, and uses encrypted strings and runtime API resolution to hinder analysis. Encryption of accessible network shares does not constitute autonomous propagation; analyzed variants lack autonomous lateral-movement functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dharma, a family of ransomware first spotted in 2016, continues to be a threat to many organizations—especially small and medium-sized businesses.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Dharma is typically deployed manually through RDP using weak or leaked credentials.
“Dharma, Phobos, and GlobeImposter commonly target small and mid-sized organizations, often through exposed remote desktop services.”
Dharma is typically deployed manually through RDP using weak or leaked credentials.
It then copies itself to the %System% directory using the original filename and creates autorun registry entries under HKLM and HKCU.
“Dharma, Phobos, and GlobeImposter commonly target small and mid-sized organizations, often through exposed remote desktop services.”
Dharma is typically deployed manually through RDP using weak or leaked credentials.
Dharma uses the RC4 stream cipher to decrypt embedded strings that contain Windows API function names.
When executed, Dharma uses the RC4 stream cipher to decrypt embedded strings that contain Windows API function names. It resolves these function addresses at runtime.
Fileless delivery also adds a further challenge in removing this threat, as it leaves no trace after execution.
First was the execution of a bat file called shadow.bat, which deletes shadow files vssadmin delete shadows /all
It stops database services such as Firebird and MSSQL, terminates processes including postgres.exe, mysqld.exe, sqlservr.exe, and Outlook.
Many of the hospital's records were encrypted due to the attack, and these included files containing patient information such as names, home addresses, dates of birth, social security numbers, driver license numbers, credit card information, phone numbers, and medical data.
It would be unusual for ransomware to encrypt and then exfiltrate information should the malware's purpose be simply to secure a blackmail payment. However, as the threat actor was present on ABH servers and details are thin on the ground, it is possible this data has made its way into the wrong hands.
“Successful data encryption also rose to 56 per cent of attacks” and recovery requires restoring data and systems after ransomware encrypts them.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family commonly targeting small and mid-sized organizations, often via exposed remote desktop services; some older versions have public decryptors.
Ransomware referenced in an anecdotal extortion case as the variant used by a Chinese-attributed group; described as generally having fairly reliable forecastable outcomes at the time.
Ransomware observed in campaigns that weaponize legitimate signed utilities to disable security tools and support ransomware execution.
Ransomware family mentioned as leveraging IOBit Unlocker in campaigns to aid attack execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.