Crysis, also widely referred to as Dharma in later reporting and lineage discussions, is a Windows ransomware family associated with both opportunistic and targeted intrusions. It encrypts victim files, including data on local systems and accessible network shares, and commonly renames encrypted files using victim-specific identifiers and attacker contact information. Multiple variants have been observed, including later Dharma-branded and extension-based subvariants such as the Arena variant. Crysis has also been identified as the ancestral family for Phobos and is frequently discussed together with Dharma because of overlapping code lineage, operational similarities, and detection naming.
Crysis has been repeatedly linked to manual deployment following compromise of exposed Remote Desktop Protocol services. Operators have used brute-force or dictionary attacks against weak RDP credentials, then logged in interactively to deploy ransomware and, in some cases, move laterally to additional internal systems. Reporting also ties Crysis delivery to phishing-enabled intrusion chains, including campaigns in which a Negasteal or Agent Tesla variant retrieved and decoded the ransomware payload for fileless execution. In enterprise intrusions, actors associated with Crysis have used credential theft and reconnaissance tooling such as Mimikatz, NirSoft utilities, and Process Hacker to expand access, assess the environment, and support follow-on encryption activity.
Behaviorally, Crysis encrypts targeted files and may attempt to delete shadow copies to inhibit recovery. Some variants establish persistence so encryption can recur at logon or affect newly created files. The family has appeared in targeted ransomware incidents alongside broader post-compromise tradecraft such as reconnaissance, credential harvesting, lateral movement, and defense evasion. It has been observed in attacks against businesses and enterprise environments, and it has remained relevant through derivative families and ransomware-as-a-service ecosystems built from its code base.
A notable event in the family’s history was the public release of master decryption keys in 2016, which enabled free decryption for affected victims through updated security tooling. Despite that milestone, later Dharma/Crysis variants and descendants continued to circulate, and not all subsequent variants were decryptable at the time they were discovered.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
61 Copies and executes a published proof-of-concept privilege escalation exploit (CVE-2018-8120) —either the 32-bit (x86.exe) or 64-bit (x64.exe) version.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Dharma is typically deployed manually through RDP using weak or leaked credentials.
Dharma is typically deployed manually through RDP using weak or leaked credentials.
It then copies itself to the %System% directory using the original filename and creates autorun registry entries under HKLM and HKCU.
It is most likely distributed through exposed Remote Desktop Protocol (RDP)... The new ransomware is most likely spread through RDP... Like Nefilim, many of these ransomware attacks abuse exposed RDP ports.
Dharma is typically deployed manually through RDP using weak or leaked credentials.
Dharma uses the RC4 stream cipher to decrypt embedded strings that contain Windows API function names.
When executed, Dharma uses the RC4 stream cipher to decrypt embedded strings that contain Windows API function names. It resolves these function addresses at runtime.
Fileless delivery also adds a further challenge in removing this threat, as it leaves no trace after execution.
First was the execution of a bat file called shadow.bat, which deletes shadow files vssadmin delete shadows /all
It stops database services such as Firebird and MSSQL, terminates processes including postgres.exe, mysqld.exe, sqlservr.exe, and Outlook.
As Process Hacker can be used to gain an overview of processes currently being used...
Many Dharma intrusions begin when threat actors gain access to a Windows system through Remote Desktop Protocol (RDP).
Crysis and Venus are both major ransomware types known to target externally exposed remote desktop services. Actual logs from the AhnLab Smart Defense (ASD) infrastructure also show attacks being launched through RDP. | Using the collected account information, lateral movement can occur to other systems within the network. In an actual attack case involving Crysis, the threat actor used RDP for lateral movement into other systems within the network.
Many of the hospital's records were encrypted due to the attack, and these included files containing patient information such as names, home addresses, dates of birth, social security numbers, driver license numbers, credit card information, phone numbers, and medical data.
It would be unusual for ransomware to encrypt and then exfiltrate information should the malware's purpose be simply to secure a blackmail payment. However, as the threat actor was present on ABH servers and details are thin on the ground, it is possible this data has made its way into the wrong hands.
As with most strains, the malware was able to encrypt files and then demanded a ransom payment in return for access. Many of the hospital's records were encrypted due to the attack. | The "unauthorized party" deployed malicious code and infected the hospital's systems with a strain of ransomware. The ransomware at fault for the infection is known as Dharma.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family referenced as the lineage/source family from which Phobos is derived.
Named as one of the ransomware families involved in a ransomware campaign in Colombia.
Ransomware used by the same threat actor in RDP-driven attacks. It was deployed first to encrypt compromised systems and also used for lateral movement-driven encryption of other systems on the network.
Ransomware family/lineage referenced via the Crysis/Dharma/Phobos naming cluster as a common holiday-season threat.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.