Karma is a Windows ransomware family and associated ransomware operation first observed in 2021. It encrypts victim files, appends a distinctive ransomware extension, drops ransom notes, and in some variants changes the desktop wallpaper. Ransom notes claim network compromise, data theft, and file encryption, and threaten public disclosure of stolen information, indicating use in double-extortion campaigns.
Technical analysis shows Karma evolving rapidly across closely timed builds. Observed variants enumerate local drives, selectively exclude system directories and executable-related file types, and support encrypting either the full system or specific files or directories via command-line parameters. The malware uses multithreaded encryption and creates a mutex to prevent multiple concurrent executions. Researchers observed changes over time in its cryptographic implementation, including use of ChaCha20 or Salsa20 for file encryption and elliptic-curve cryptography to protect per-file keys. Later variants also added wallpaper modification and revised ransom-note formats.
Karma has notable code and lineage relationships within the Nemty/JSWorm ransomware cluster. It has been assessed as closely related to, and likely part of the evolutionary path leading to, Nokoyawa. Strong similarities have also been reported with JSWorm and GangBang/Milihpen variants, supporting the view that Karma belongs to a broader ransomware development ecosystem rather than being an isolated family.
Operational reporting links Karma to enterprise intrusions involving exploitation of public-facing Microsoft Exchange vulnerabilities, followed by use of compromised administrative accounts, lateral movement, data exfiltration, and ransom-note deployment. In at least one documented healthcare intrusion, Karma exfiltrated data and issued extortion demands without encrypting systems. Reporting also links the broader operator ecosystem around Karma to other ransomware-as-a-service activity associated with Nemty, Nokoyawa, and related crews. The malware targets Windows environments and has been used against organizations across multiple industries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Both attackers gained entry via “ProxyShell” exploits (targeting CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 on Microsoft’s Exchange Server platform). | The first ransomware group, identified as Karma, exfiltrated data but did not encrypt the target’s systems... Then the Karma malware was deployed, using the compromised Administrator account.
Both attackers gained entry via “ProxyShell” exploits (targeting CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 on Microsoft’s Exchange Server platform). | The first ransomware group, identified as Karma, exfiltrated data but did not encrypt the target’s systems... Then the Karma malware was deployed, using the compromised Administrator account.
Both attackers gained entry via “ProxyShell” exploits (targeting CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 on Microsoft’s Exchange Server platform). | The first ransomware group, identified as Karma, exfiltrated data but did not encrypt the target’s systems... Then the Karma malware was deployed, using the compromised Administrator account.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Inside this project, the three helped develop Karma and Karma 2, two iOS zero-click exploits. Designed to target iPhones, Reuters said the two exploits were used by UAE officials to spy on dissidents, reporters, and government opposition leaders.
Inside this project, the three helped develop Karma and Karma 2, two iOS zero-click exploits. Designed to target iPhones, Reuters said the two exploits were used by UAE officials to spy on dissidents, reporters, and government opposition leaders.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Google even advertises for the extension, listing it in the “Editors’ Picks extensions” collection... most of them carry the “Featured” badge.
Like Karma, Nokoyawa accepts different command line parameters, although in the latter they are documented by the developer via a -help command.
Google even advertises for the extension, listing it in the “Editors’ Picks extensions” collection... most of them carry the “Featured” badge.
Five years ago I discovered that Avast browser extensions were spying on their users... also in October I wrote about the Karma extension spying on users... The extension remains available on Chrome Web Store unchanged, it will still notify their server about every web page you visit.
Users are not being notified about their browsing data being collected and sold, except for a note buried in their privacy policy... The Karma extension remains available on Chrome Web Store unchanged, it will still notify their server about every web page you visit.
Parameter Functionality -help Prints command line options for execution of ransomware. -network Encrypts local and network shares. -file Encrypts specified file. -dir Encrypts specified directory. If the ransomware is executed without any parameter, it then encrypts the machine without enumerating and encrypting network resources.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Nemty ransomware variant used as the predecessor/basis for Nokoyawa. It encrypts victim data, uses a similar multithreaded encryption design and Salsa20-based scheme, and includes ransom notes threatening data leaks.
A wireless rogue access point technique/framework that responds to client probe requests for previously known SSIDs, automatically impersonating those networks to attract victim devices.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Ransomware that enumerates local drives, encrypts files, drops ransom notes, changes the desktop wallpaper in some variants, and uses ChaCha20 or Salsa20 for file encryption with ECC-protected keys. It also threatens data leakage if victims do not pay.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.