Dharma, also known as CrySiS or Crysis, is a long-running Windows ransomware family first observed in 2016 and widely operated through a ransomware-as-a-service model. It has remained especially active against small and medium-sized organizations, though victims have included healthcare entities, ports, breweries, and other businesses worldwide. Multiple criminal affiliates have used the malware, and law-enforcement reporting has linked Dharma deployments to organized ransomware actors involved in large-scale intrusion activity.
Dharma is most strongly associated with manual intrusions through exposed or weakly protected Remote Desktop Protocol access, often using stolen, leaked, or brute-forced credentials. Spam email distribution has also been documented, including campaigns that delivered password-protected archives. Some variants have used decoy software installation to distract victims while encryption runs in the background. Operational reporting consistently describes Dharma attacks as hands-on-keyboard compromises rather than purely opportunistic self-spreading outbreaks.
On execution, Dharma establishes persistence on Windows systems by copying itself into system or Startup locations and creating autorun entries. It has been observed creating mutexes to prevent duplicate execution, decrypting embedded strings at runtime, stopping services and terminating processes that may lock files, and deleting shadow copies to inhibit recovery. It encrypts files using AES with per-file keys protected by an embedded RSA public key, then drops ransom instructions and demands payment for decryption. Public reporting has repeatedly stated that recovery without the attackers’ key is generally not feasible for modern variants absent an implementation flaw.
Beyond encryption, Dharma-associated intrusions frequently involve broader post-compromise activity. Reporting on affiliate toolkits shows use of credential theft utilities, brute-force tooling, network and Active Directory reconnaissance, antivirus disruption, and manual deployment workflows. In some incidents, operators used administrative tools and scripts to enumerate shares, clear logs, kill applications, and prepare systems for encryption. Sophos documented a standardized affiliate toolkit and attack scripts that lowered the skill barrier for operators while preserving dependence on the RaaS backend for decryption-key retrieval.
Dharma is closely related to the CrySiS lineage and has notable technical and operational overlap with Phobos, which has often been described as a derivative or close variant. Source-code leakage in 2020 likely contributed to continued variant proliferation. Overall, Dharma remains a durable ransomware ecosystem centered on Windows environments, manual remote-access compromise, persistence, defense evasion, credential abuse, and file encryption for extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
61 Copies and executes a published proof-of-concept privilege escalation exploit (CVE-2018-8120) —either the 32-bit (x86.exe) or 64-bit (x64.exe) version. | Dharma, a family of ransomware first spotted in 2016, continues to be a threat to many organizations—especially small and medium-sized businesses.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Dharma is typically deployed manually through RDP using weak or leaked credentials.
According to the MITRE CAPEC database, adversaries commonly use stolen credentials to log in to remote services such as Remote Desktop Protocol (RDP).
Dharma is typically deployed manually through RDP using weak or leaked credentials.
It then copies itself to the %System% directory using the original filename and creates autorun registry entries under HKLM and HKCU.
According to the MITRE CAPEC database, adversaries commonly use stolen credentials to log in to remote services such as Remote Desktop Protocol (RDP).
Dharma is typically deployed manually through RDP using weak or leaked credentials.
Dharma uses the RC4 stream cipher to decrypt embedded strings that contain Windows API function names.
When executed, Dharma uses the RC4 stream cipher to decrypt embedded strings that contain Windows API function names. It resolves these function addresses at runtime.
Fileless delivery also adds a further challenge in removing this threat, as it leaves no trace after execution.
First was the execution of a bat file called shadow.bat, which deletes shadow files vssadmin delete shadows /all
It stops database services such as Firebird and MSSQL, terminates processes including postgres.exe, mysqld.exe, sqlservr.exe, and Outlook.
Many of the hospital's records were encrypted due to the attack, and these included files containing patient information such as names, home addresses, dates of birth, social security numbers, driver license numbers, credit card information, phone numbers, and medical data.
It would be unusual for ransomware to encrypt and then exfiltrate information should the malware's purpose be simply to secure a blackmail payment. However, as the threat actor was present on ABH servers and details are thin on the ground, it is possible this data has made its way into the wrong hands.
CISA defines ransomware as “an ever-evolving form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. Malicious actors then demand ransom in exchange for decryption.” | Once launched, the malware may connect to a command-and-control server to enable the criminals to move laterally across networks and encrypt and/or exfiltrate the organization’s data.
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information.
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities... killing security software processes or services, modifying / deleting Registry keys or configuration files... Adversaries may also disable updates...
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced in an anecdotal extortion case as the variant used by a Chinese-attributed group; described as generally having fairly reliable forecastable outcomes at the time.
Ransomware observed in campaigns that weaponize legitimate signed utilities to disable security tools and support ransomware execution.
Ransomware family mentioned as leveraging IOBit Unlocker in campaigns to aid attack execution.
Ransomware family listed among campaigns that neutralize defenses with legitimate tools before deploying encryption payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.