Sophos reported that the Dharma ransomware operation, also known as CrySis, continues to profit as a ransomware-as-a-service scheme by targeting small and medium-sized businesses through high-volume intrusions. Investigators said many attacks begin with compromised or poorly secured Remote Desktop Protocol (RDP) access, often using stolen credentials purchased on criminal forums, before affiliates move deeper into victim networks and deploy the ransomware payload.
The operation relies on a standardized affiliate toolkit built around a menu-driven PowerShell script, toolbelt.ps1, that automates much of the attack chain for low-skill operators. Sophos said the toolkit combines Windows utilities, legitimate freeware, public exploits, and custom scripts for credential theft with Mimikatz, reconnaissance, Active Directory discovery, lateral movement, antivirus disruption, Tor-based communications, and final encryption, while a two-stage decryption process keeps affiliates dependent on core operators for key retrieval and victim support.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
A Dharma ransomware variant discovered in March 2021 was reported to append the ".biden" extension to encrypted files. The reference describes this as part of the long-running Dharma/CrySiS ransomware-as-a-service family.
According to statistics cited from Coveware in the report, Dharma ransom demands averaged $8,620 in December 2019, illustrating the group's lower-demand, high-volume business model.
The report states that Dharma ransomware, also known as CrySis, was first spotted in 2016 and went on to become a long-running ransomware threat.
SophosLabs and Sophos MTR documented three recent Dharma intrusions that revealed a common affiliate toolkit centered on the menu-driven PowerShell script toolbelt.ps1.
The report says a source code package for one Dharma variant was offered for sale on Russian-language criminal forums through an intermediary for $2,000 in March.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.