Dharma, also known as CrySiS, is a Windows ransomware family active since 2016 and commonly operated as ransomware-as-a-service (RaaS). It has predominantly targeted small and medium-sized organizations worldwide, including healthcare and other businesses. Affiliates commonly obtain initial access by abusing exposed Remote Desktop Protocol services, including through weak, stolen, leaked, or brute-forced credentials; phishing and malicious spam campaigns have also delivered Dharma payloads. Some campaigns used a legitimate software installer as a decoy while encryption executed in the background.
Dharma is generally deployed manually after access to a victim environment is obtained. It establishes persistence through Windows Run keys and Startup-folder copies, creates mutexes to prevent duplicate execution, and can obfuscate embedded API names. Before encryption, variants may terminate database, email, and other processes, stop services that could lock files, and delete Windows Volume Shadow Copies to inhibit recovery. It encrypts a broad range of document, archive, database, media, image, and source-code files on local drives, accessible network shares, and newly connected drives, while excluding selected boot-critical files. Variants use hybrid encryption, with AES encryption for file contents and an embedded RSA public key to protect per-file encryption keys. Encrypted files are renamed with variant-specific extensions and victim identifiers, and ransom notes direct victims to contact the operators for payment and decryption.
Dharma traditionally focused on encryption-based extortion and was not associated with data theft in earlier reporting. It has been linked to multiple criminal investigations alongside deployments of LockerGoga and MegaCortex, but the family is distributed through affiliates and cannot be attributed to a single consistent operator. Phobos is a closely related ransomware operation and widely regarded as a Dharma/CrySiS derivative or successor with substantial technical and operational overlap.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dharma, a family of ransomware first spotted in 2016, continues to be a threat to many organizations—especially small and medium-sized businesses.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Dharma is typically deployed manually through RDP using weak or leaked credentials.
“Dharma, Phobos, and GlobeImposter commonly target small and mid-sized organizations, often through exposed remote desktop services.”
Dharma is typically deployed manually through RDP using weak or leaked credentials.
It then copies itself to the %System% directory using the original filename and creates autorun registry entries under HKLM and HKCU.
“Dharma, Phobos, and GlobeImposter commonly target small and mid-sized organizations, often through exposed remote desktop services.”
Dharma is typically deployed manually through RDP using weak or leaked credentials.
Dharma uses the RC4 stream cipher to decrypt embedded strings that contain Windows API function names.
When executed, Dharma uses the RC4 stream cipher to decrypt embedded strings that contain Windows API function names. It resolves these function addresses at runtime.
Fileless delivery also adds a further challenge in removing this threat, as it leaves no trace after execution.
First was the execution of a bat file called shadow.bat, which deletes shadow files vssadmin delete shadows /all
It stops database services such as Firebird and MSSQL, terminates processes including postgres.exe, mysqld.exe, sqlservr.exe, and Outlook.
Many of the hospital's records were encrypted due to the attack, and these included files containing patient information such as names, home addresses, dates of birth, social security numbers, driver license numbers, credit card information, phone numbers, and medical data.
It would be unusual for ransomware to encrypt and then exfiltrate information should the malware's purpose be simply to secure a blackmail payment. However, as the threat actor was present on ABH servers and details are thin on the ground, it is possible this data has made its way into the wrong hands.
“Successful data encryption also rose to 56 per cent of attacks” and recovery requires restoring data and systems after ransomware encrypts them.
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities... killing security software processes or services, modifying / deleting Registry keys or configuration files... Adversaries may also disable updates...
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family commonly targeting small and mid-sized organizations, often via exposed remote desktop services; some older versions have public decryptors.
Ransomware referenced in an anecdotal extortion case as the variant used by a Chinese-attributed group; described as generally having fairly reliable forecastable outcomes at the time.
Ransomware observed in campaigns that weaponize legitimate signed utilities to disable security tools and support ransomware execution.
Ransomware family mentioned as leveraging IOBit Unlocker in campaigns to aid attack execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.