Karma
Karma is a threat actor/persona referenced in two distinct contexts in the provided content. First, it is described as a criminal crew involved in ransomware activity: Sophos reported that both Conti and Karma accessed a Canadian healthcare organization via the ProxyShell exploit, with Karma leaving a ransom note but not encrypting files, while Conti later encrypted much of the victim’s data. Second, more recent reporting cited in the content describes Karma, also referred to as KarmaBelow80, as part of a coordinated cyber influence ecosystem aligned with Iran’s Ministry of Intelligence and Security (MOIS). DomainTools Investigations assessed Homeland Justice, Karma/KarmaBelow80, and Handala Hack as interchangeable operational veneers rather than distinct hacktivist groups, with public-facing domains and Telegram channels used for dissemination and amplification. The content also states that Karma was used for targeted Israeli operations, and notes comparable operational sequencing with attacks conducted under the Homeland Justice persona against Albania in 2022. Based on the provided material, known aliases include Karma and KarmaBelow80.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Health Care Equipment & Services
Where they target
Geographies tied to known operations.
- 🇨🇦 Canada
Tradecraft
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of an Iran-aligned coordinated cyber influence ecosystem used for hack-and-leak, influence, messaging amplification, and operational activity.
An operational persona/brand used for targeted Israeli operations within the same Iranian-linked activity set discussed in the article.
Persona referenced as part of campaigns showing similar sequencing between initial access and public-facing disruptive operations.
Criminal crew that targeted a Canadian healthcare organization via ProxyShell, left a ransom note, but did not encrypt files before Conti also compromised the environment.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.