Skip to content
Malware family

Dharma

Dharma is a ransomware family, commonly referenced as a ransomware-as-a-service (RaaS) variant and frequently discussed alongside Phobos due to their similarity and shared affiliate-style ecosystem.

Profile source: Mallory opens in a new tab

Dharma

Family profile

Dharma is a ransomware family, commonly referenced as a ransomware-as-a-service (RaaS) variant and frequently discussed alongside Phobos due to their similarity and shared affiliate-style ecosystem. The provided content places Dharma among long-running ransomware families that remained active or widely observed through at least 2021–2023, and notes that affiliates often move between multiple RaaS programs rather than remaining loyal to one brand. Reporting cited in the content also links some activity around 8base to former Dharma and Phobos affiliates.

Operationally, the content associates Dharma with campaigns that begin through phishing emails or compromised credentials. It is characterized as affecting smaller organizations in some reporting, including “spray and pray” style attacks and attacks against small companies with exposed RDP, while other reporting notes its presence among top ransomware variants observed in incident-response datasets. The content also states Dharma was among variants associated with re-extortion, where victims may be pressured for additional payment after an initial ransom.

A recurring theme in the source material is Dharma operators’ abuse of legitimate, often digitally signed administrative or troubleshooting tools to disable defenses before ransomware deployment. Tools explicitly mentioned in Dharma-linked campaigns include IOBit Unlocker, Process Hacker, PowerRun, YDArk, Mimikatz, and Unlock_IT. According to the cited reporting, these tools were used to kill antivirus or EDR processes, gain SYSTEM- or kernel-level access, steal credentials, and erase logs or forensic traces. More generally, the content ties Dharma to defense-impairment behavior such as abusing legitimate rootkit-removal kits and low-level tools to disable security products.

The content also includes ecosystem and law-enforcement context. Ukraine’s Cyber Police reportedly detained suspects in November 2022 in connection with LockerGoga, MegaCortex, Hive, and Dharma ransomware attacks, and later investigations and arrests in Ukraine were again described as involving the Dharma ransomware family. Financial reporting cited in the content includes Dharma in ransomware payment analyses, with one Chainalysis dataset characterizing Dharma as a low-level RaaS strain used against smaller targets and listing very small average and median payment sizes. Only high-confidence information directly stated in the content is included here.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • LU1

Leading providers

  • Ghosty Networks LLC1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

Dharma in ATT&CK

3 distinct techniques

Reporting

Research mentioning Dharma

Apr 2
Scworld

Ransomware attackers increasingly exploit legitimate IT tools, bypassing antivirus | brief | SC Media

This tactic was observed in campaigns involving LockBit Black 3.0 and Dharma ransomware.

Apr 1
Hackread

Ransomware Groups Exploit Legit IT Tools to Bypass Antivirus

IOBit Unlocker has been used in Dharma campaigns.

Mar 31
Cyber Security News

Hackers Weaponize Legitimate Windows Tools to Disable Antivirus Before Ransomware Attacks - Cyber Security News

Seqrite researchers identified this growing pattern and noted that the abuse of legitimate low-level tools has become a defining feature of today’s ransomware campaigns — from LockBit 3.0 and BlackCat to Dharma, Phobos, and MedusaLocker.

Oct 23
Recorded Future

Dark Covenant 3.0: Controlled Impunity and Russia’s Cybercriminals

...existing ransomware families such as LockBit, CryLock, Xorist, Proton, GlobeImposter, Chaos, Makop, MedusaLocker, Djvu, Dharma, and more.

Sep 10
Risky Biz Rss

Risky Bulletin: US charges major ransomware figure

In November 2022, Ukraine's Cyber Police detained five suspects involved in LockerGoga, MegaCortex, Hive, and Dharma ransomware attacks.

Jun 20
The Hacker News

Qilin Ransomware Adds "Call Lawyer" Feature to Pressure Victims for Larger Ransoms

Authorities said they were able to trace the suspect following a forensic analysis of equipment seized in a previous raid that took place in November 2023 targeting members of the LockerGoga, MegaCortex, and Dharma ransomware families.

Jun 19
Bleeping Computer

Ryuk ransomware’s initial access expert extradited to the U.S.

This operation led to the identification, seizure of devices, and arrest of multiple cybercriminals residing in Ukraine for their involvement in the LockerGoga, MegaCortex, Hive, and Dharma ransomware families.

Sep 14
Sekoia

Sekoia.io mid-2023 Ransomware Threat Landscape

...8base ... linked either to former Dharma and Phobos affiliates...

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.