Karma is a ransomware-associated threat actor first observed in 2021 and known for both file-encrypting and data-theft extortion activity. The group has operated malware that encrypts files across local drives, appends a distinctive extension, drops ransom notes, and in some variants changes the victim desktop wallpaper. Ransom notes have threatened publication of stolen data on a leak site and outreach to journalists if victims do not pay, indicating extortion beyond encryption alone. In at least one documented intrusion against a healthcare organization, Karma exfiltrated data and issued ransom demands without encrypting systems, explicitly framing the operation as theft-based extortion. Karma’s malware development showed rapid iteration across closely timed builds. Observed variants enumerated drives, excluded selected system directories and file types, created a mutex to prevent duplicate execution, and later added command-line targeting options. Researchers documented changes in threading behavior, ransom-note naming, and cryptographic implementation, including shifts between ChaCha20 and Salsa20 for file encryption and changes in elliptic-curve cryptography components. The malware has also been associated with discovery and anti-recovery or defense-impairment behaviors mapped to ATT&CK techniques such as file and directory discovery, network share discovery, disabling or modifying security tools, and inhibiting system recovery. Karma has been linked to intrusion activity involving exploitation of Microsoft Exchange ProxyShell vulnerabilities for initial access in at least one case, followed by persistence, lateral movement, data staging, and exfiltration. In the Canadian healthcare incident, the actor used compromised administrative access to move within the environment, exfiltrate archived data, and distribute ransom notes. Reporting has also noted similarities between Karma and other ransomware operations including Nokoyawa, and especially strong code and configuration overlap with the JSWorm lineage, including NEMTY, Nefilim, and GangBang or Milihpen variants. Separately from the ransomware actor, the name Karma has also been used as a persona in Iranian information and disruptive cyber operations targeting Israel. Reporting has described Karma or KarmaBelow80 alongside Homeland Justice and Handala as part of a coordinated influence ecosystem aligned with Iran’s Ministry of Intelligence and Security, and has stated that Karma was used for targeted Israeli operations. Because the same name has been applied to both a ransomware actor and an Iran-aligned operational persona, attribution under the Karma label is context-dependent and should be handled carefully.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation active from at least June 2021 that rapidly iterated its malware, encrypted victim files, dropped ransom notes, threatened data leaks, and used double-extortion tactics.
Part of an Iran-aligned coordinated cyber influence ecosystem used for hack-and-leak, influence, messaging amplification, and operational activity.
An operational persona/brand used for targeted Israeli operations within the same Iranian-linked activity set discussed in the article.
Persona referenced as part of campaigns showing similar sequencing between initial access and public-facing disruptive operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.