Karma is an overloaded name used in the provided content for at least three distinct malicious/security-relevant contexts. First, it refers to an iPhone espionage capability reportedly used by the UAE’s Project Raven. Reuters and later DOJ-related reporting describe Karma and Karma 2 as iOS zero-click exploits introduced around 2016, used by UAE officials and contractors associated with DarkMatter to remotely compromise iPhones by submitting a target phone number or email address, without requiring the victim to click a link. Reported collection included photos, emails, text messages, location data, and saved passwords; former operatives said it did not work on Android and did not intercept phone calls. Targets reportedly included activists, diplomats, dissidents, journalists, opposition figures, and rival foreign leaders. Apple security updates by the end of 2017 reportedly made Karma far less effective. Reuters said the creator of Karma was unknown.
Second, Karma is referenced as a ransomware operation/RaaS platform. The content links the alias "salfetka" / "rinc" / "farnetwork" to Nokoyawa, JSWORM, Nefilim, Karma, and Nemty ransomware operations, and separately states that Volodymyr Tymoshchuk was linked to or involved with JSWORM, Karma, Nemty, and Nokoyawa ransomware gangs/RaaS platforms. Another report cited in the content says a criminal crew called Karma exploited ProxyShell against a Canadian healthcare organization, left a ransom note demanding payment, but did not encrypt the victim’s files while Conti was simultaneously active in the same environment. The content also notes TTP overlap between INC Ransom and historical RaaS operations including Nemty, Nemty X, Karma, and Nokoyawa.
Third, the content uses KARMA in the wireless-security sense: a rogue access point technique that responds to probe requests for previously saved SSIDs and automatically impersonates those networks. In this context, KARMA attacks are associated with Evil Twin/MITM-style credential harvesting and traffic interception, and a detection hallmark is multiple SSIDs originating from a single MAC address or BSSID.
Because the supplied material conflates these separate uses, high-confidence attribution should distinguish among: (1) Karma/Karma 2 iOS zero-click exploitation used by Project Raven/UAE-linked operators; (2) Karma ransomware/RaaS references tied to broader ransomware ecosystems and actors including Tymoshchuk-linked personas; and (3) KARMA wireless rogue-AP behavior used in Evil Twin attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Both Conti and another criminal crew called Karma hit the unidentified org through the ProxyShell exploit – though while Karma left a ransom note demanding payment, having not encrypted the organisation's files...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Inside this project, the three helped develop Karma and Karma 2, two iOS zero-click exploits. Designed to target iPhones, Reuters said the two exploits were used by UAE officials to spy on dissidents, reporters, and government opposition leaders.
Inside this project, the three helped develop Karma and Karma 2, two iOS zero-click exploits. Designed to target iPhones, Reuters said the two exploits were used by UAE officials to spy on dissidents, reporters, and government opposition leaders.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Google even advertises for the extension, listing it in the “Editors’ Picks extensions” collection... most of them carry the “Featured” badge.
Karma did not require a target to click on a link sent to an iPhone... In 2016 and 2017, Karma was used to obtain photos, emails, text messages and location information from targets’ iPhones.
Karma was described as a tool that could remotely grant access to iPhones simply by uploading phone numbers or email accounts into an automated targeting system... unlike many exploits, Karma did not require a target to click on a link sent to an iPhone.
Google even advertises for the extension, listing it in the “Editors’ Picks extensions” collection... most of them carry the “Featured” badge.
Five years ago I discovered that Avast browser extensions were spying on their users... also in October I wrote about the Karma extension spying on users... The extension remains available on Chrome Web Store unchanged, it will still notify their server about every web page you visit.
Users are not being notified about their browsing data being collected and sold, except for a note buried in their privacy policy... The Karma extension remains available on Chrome Web Store unchanged, it will still notify their server about every web page you visit.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A wireless rogue access point technique/framework that responds to client probe requests for previously known SSIDs, automatically impersonating those networks to attract victim devices.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Referenced as a historical RaaS/ransomware operation with TTP overlap to INC Ransom (no additional details provided).
Karma is a ransomware family associated with the same administrator as JSWORM, Nokoyawa, and Nemty.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.