Karma is a Windows ransomware family first observed in 2021 and associated with double-extortion activity. It encrypts files across local drives, appends a distinctive ransomware extension, drops ransom notes, and in some variants changes the victim’s desktop wallpaper. Ransom communications threaten publication of stolen data on a leak site if payment is not made, indicating use in extortion operations that combine data theft with encryption pressure.
Technical analysis shows Karma as a console-based x86 executable written in C or C++. It enumerates logical drives, supports command-line targeting of specific files or directories, creates a mutex to prevent multiple concurrent executions, and excludes selected system directories and file types from encryption to preserve system operability. Observed variants evolved rapidly over short periods, with changes in threading design, ransom-note naming, excluded extensions, and cryptographic implementation. Reported versions used per-file symmetric encryption with ChaCha20 or Salsa20 and protected encryption material with embedded elliptic-curve public keys, including transitions between different ECC curves.
Karma has notable code and design overlap with the Nemty and JSWorm ransomware lineage, and multiple researchers have assessed Nokoyawa as sharing code with or evolving from the Karma strain rather than being closely related to Hive. Similarities include multithreaded encryption architecture, Base64-encoded configuration elements, dynamic cryptographic library loading, and use of ephemeral elliptic-curve key exchange to derive file-encryption keys. The family has also been referenced in connection with broader ransomware-as-a-service ecosystems and operators linked to Nemty, JSWorm, Nefilim, and Nokoyawa.
Karma has been observed in enterprise intrusions involving exploitation of public-facing applications, including Exchange ProxyShell in at least one reported incident. In that case, operators used compromised administrative access to deploy ransom notes and exfiltrate data, while claiming not to encrypt systems because the victim was in the health-care sector. More broadly, Karma has targeted organizations across multiple industries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Both attackers gained entry via “ProxyShell” exploits (targeting CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 on Microsoft’s Exchange Server platform). | The first ransomware group, identified as Karma, exfiltrated data but did not encrypt the target’s systems... Then the Karma malware was deployed, using the compromised Administrator account.
Both attackers gained entry via “ProxyShell” exploits (targeting CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 on Microsoft’s Exchange Server platform). | The first ransomware group, identified as Karma, exfiltrated data but did not encrypt the target’s systems... Then the Karma malware was deployed, using the compromised Administrator account.
Both attackers gained entry via “ProxyShell” exploits (targeting CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207 on Microsoft’s Exchange Server platform). | The first ransomware group, identified as Karma, exfiltrated data but did not encrypt the target’s systems... Then the Karma malware was deployed, using the compromised Administrator account.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Inside this project, the three helped develop Karma and Karma 2, two iOS zero-click exploits. Designed to target iPhones, Reuters said the two exploits were used by UAE officials to spy on dissidents, reporters, and government opposition leaders.
Inside this project, the three helped develop Karma and Karma 2, two iOS zero-click exploits. Designed to target iPhones, Reuters said the two exploits were used by UAE officials to spy on dissidents, reporters, and government opposition leaders.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Google even advertises for the extension, listing it in the “Editors’ Picks extensions” collection... most of them carry the “Featured” badge.
Like Karma, Nokoyawa accepts different command line parameters, although in the latter they are documented by the developer via a -help command.
Google even advertises for the extension, listing it in the “Editors’ Picks extensions” collection... most of them carry the “Featured” badge.
Five years ago I discovered that Avast browser extensions were spying on their users... also in October I wrote about the Karma extension spying on users... The extension remains available on Chrome Web Store unchanged, it will still notify their server about every web page you visit.
Users are not being notified about their browsing data being collected and sold, except for a note buried in their privacy policy... The Karma extension remains available on Chrome Web Store unchanged, it will still notify their server about every web page you visit.
Parameter Functionality -help Prints command line options for execution of ransomware. -network Encrypts local and network shares. -file Encrypts specified file. -dir Encrypts specified directory. If the ransomware is executed without any parameter, it then encrypts the machine without enumerating and encrypting network resources.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Nemty ransomware variant used as the predecessor/basis for Nokoyawa. It encrypts victim data, uses a similar multithreaded encryption design and Salsa20-based scheme, and includes ransom notes threatening data leaks.
A wireless rogue access point technique/framework that responds to client probe requests for previously known SSIDs, automatically impersonating those networks to attract victim devices.
Named ransomware operation referenced in connection with aliases linked to the seller of INC source code.
Ransomware that enumerates local drives, encrypts files, drops ransom notes, changes the desktop wallpaper in some variants, and uses ChaCha20 or Salsa20 for file encryption with ECC-protected keys. It also threatens data leakage if victims do not pay.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.