Dharma is a ransomware threat actor and associated ransomware operation known for opportunistic intrusions, commonly involving exposed Remote Desktop Protocol access and attacks against smaller organizations or single systems rather than large-scale enterprise-wide compromises. It is frequently discussed alongside closely related or overlapping activity involving Crysis and, in some reporting, affiliates later linked to operations such as 8Base and Phobos. The actor has been observed using legitimate administrative and troubleshooting tools during intrusions for reconnaissance, defense evasion, and post-compromise operations. Reported tradecraft includes network scanning with Advanced IP Scanner; disabling or impairing endpoint protections with utilities such as Defender Control; abusing signed dual-use tools to terminate antivirus processes; obtaining elevated or kernel-level execution through legitimate or semi-legitimate utilities; credential theft with tools such as Mimikatz; and log clearing or other anti-forensic actions. Use of trusted tools to suppress security controls and blend into normal administration is a recurring characteristic. Dharma activity is associated with common ransomware lifecycle behaviors including initial access, internal reconnaissance, credential theft, defense evasion, lateral movement, data exfiltration, and encryption-based extortion. Reporting also links the operation to laundering ransom proceeds through cryptocurrency mixing services. Some reporting references actors believed to be Chinese using Dharma ransomware in at least one extortion case, but this does not establish Dharma itself as a confirmed China-based threat actor. Dharma is best characterized as a financially motivated ransomware operation or ecosystem rather than a nation-state group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the ransomware used by an unnamed Chinese-attributed extortion group in a 2020 case; Dharma itself is not the main subject of the article.
Associated with ransomware campaigns using dual-use legitimate IT tools to disable security software and operate undetected.
Ransomware campaigns associated with use of the legitimate utility IOBit Unlocker to disable protections.
Referenced as a ransomware gang that used Cryptomixer to launder ransom payments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.