Dharma is a ransomware family and long-running ransomware-as-a-service operation primarily associated with opportunistic intrusions against small and mid-sized organizations. It has been repeatedly discussed alongside closely related low-tier extortion ecosystems such as Phobos and Makop, and has been used by a wide range of affiliates rather than a single exclusive threat actor. Reporting over multiple years places Dharma among prevalent ransomware strains in the broader criminal market, including incidents involving re-extortion after an initial payment and affiliate overlap with other ransomware programs.
Dharma is used to encrypt victim data for extortion and has been associated with campaigns that also involve credential theft, lateral movement, and defense evasion. Operators have been observed abusing legitimate administrative and low-level Windows utilities to disable antivirus and endpoint protections before ransomware deployment, including process-killing and unlocker tools, as well as tools used to obtain elevated or kernel-level access. Campaigns linked to Dharma have also included use of credential-dumping tooling and log-clearing utilities to hinder investigation and recovery.
Observed initial access patterns for Dharma campaigns include phishing and the use of compromised credentials. Historical reporting also associates Dharma activity with exposed remote access services and low-complexity “spray and pray” targeting of smaller victims, consistent with the economics of lower-tier RaaS operations. Victim organizations span multiple sectors, with the family frequently characterized as affecting smaller enterprises rather than exclusively targeting large strategic organizations.
Dharma has also appeared in law-enforcement reporting tied to arrests and investigations involving ransomware operators and affiliates in Ukraine. The family remains notable as an example of commoditized ransomware whose affiliates can shift between brands, reuse common tradecraft, and participate in broader extortion ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such as killing security software processes or services, modifying / deleting Registry keys or configuration files so that tools do not operate properly, or other methods to interfere with security tools scanning or reporting information.
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities... killing security software processes or services, modifying / deleting Registry keys or configuration files... Adversaries may also disable updates...
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced in an anecdotal extortion case as the variant used by a Chinese-attributed group; described as generally having fairly reliable forecastable outcomes at the time.
Ransomware observed in campaigns that weaponize legitimate signed utilities to disable security tools and support ransomware execution.
Ransomware family mentioned as leveraging IOBit Unlocker in campaigns to aid attack execution.
Ransomware family listed among campaigns that neutralize defenses with legitimate tools before deploying encryption payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.