Skip to content

Dharma

Dharma, also known as CrySiS, is a Windows ransomware family active since 2016 and operated through a ransomware-as-a-service model.

Profile source: Mallory opens in a new tab

Dharma

Family profile

Dharma, also known as CrySiS, is a Windows ransomware family active since 2016 and operated through a ransomware-as-a-service model. It has primarily targeted small and medium-sized organizations, including healthcare entities, through affiliate-led intrusions. Common initial-access methods include phishing and malicious spam, as well as manual deployment following compromise of exposed Remote Desktop Protocol services using weak, stolen, or leaked credentials.

Dharma encrypts a broad range of documents, databases, archives, media, source-code files, and files on accessible local, removable, and network-shared storage. Variants use hybrid cryptography, encrypting file content with AES and protecting per-file encryption material with an embedded RSA public key. Encrypted files are renamed with victim- and operator-specific information and a variant-specific extension, and ransom notes direct victims to contact the operators to obtain a decryptor.

Before encryption, Dharma variants commonly stop database-related services, terminate processes that may lock files, and delete Volume Shadow Copies to inhibit recovery. They may establish persistence through Windows autorun mechanisms and Startup locations. Some variants obfuscate embedded strings and dynamically resolve Windows API functions. Dharma has been observed using legitimate software installers as decoys, presenting a benign installation interface while encryption occurs in a separate process. Dharma is generally manually deployed rather than autonomously propagating laterally, although it can encrypt files on network shares reachable from the compromised host.

Capabilities

  • Brute Force
  • Defense Evasion
  • Extortion
  • Initial Access
  • Persistence
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Sep 3, 2026
Feed role
C2 / Distribution
Host form
8 IP / 3 hostnames

Leading locations

  • CN4
  • NL2
  • US2
  • KR1
  • PL1
  • RU1

Leading providers

  • Hangzhou Alibaba Advertising Co.,Ltd.2
  • Omegatech LTD2
  • CHINA UNICOM China169 Backbone1
  • CHINANET Hubei province network1
  • Cloudflare, Inc.1
  • Proton66 OOO1

Infrastructure traits

  • Hosting 8
  • Anycast 1

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to Dharma

1 CVEs

MITRE ATT&CK

Dharma in ATT&CK

25 distinct techniques

Reporting

Research mentioning Dharma

Jan 1
Sophos Threat Research

Color by numbers: inside a Dharma ransomware-as-a-service attack | SOPHOS

Sophos reported that the Dharma ransomware operation, also known as CrySis, continues to profit as a ransomware-as-a-service scheme by targeting small and medium-sized businesses through high-volume intrusions. Investigators said many attacks begin with compromised or poorly secured Remote Desktop Protocol (RDP) access, often using stolen credentials purchased on criminal forums, before affiliates move deeper into victim networks and deploy the ransomware payload. The operation relies on a standardized affiliate toolkit built around a menu-driven PowerShell script, toolbelt.ps1, that automates much of the attack chain for low-skill operators. Sophos said the toolkit combines Windows utilities, legitimate freeware, public exploits, and custom scripts for credential theft with Mimikatz, reconnaissance, Active Directory discovery, lateral movement, antivirus disruption, Tor-based communications, and final encryption, while a two-stage decryption process keeps affiliates dependent on core operators for key retrieval and victim support.

Dec 5
Acronis

Dharma (CrySiS) Ransomware: Technical Analysis, Context and Mitigation

Feb 1
Ahnlab Asec

Paradise Ransomware Distributed Through AweSun Vulnerability Exploitation - ASEC

The Paradise ransomware operation, a long-running ransomware-as-a-service family first seen in 2017, drew renewed concern after the source code for its .NET variant was leaked on the Russian-speaking XSS forum. Researchers said the leak included the Paradise builder and a decryption utility, and analysts verified the files as authentic. Although the .NET branch had seen more limited use than the native Paradise version, newly built samples were reportedly being classified as undecryptable, raising the risk that additional threat actors could repurpose the code against home users and small businesses. Subsequent intrusions showed Paradise being deployed through suspected exploitation of outdated AweSun remote-control software, alongside activity involving Sunlogin flaws, Sliver C2, Cobalt Strike, BYOVD tooling, and XMRig. In one analyzed case, the ransomware used RSA-1024 encryption, deleted Volume Shadow Copies, set persistence through a Windows Run key, prioritized database and backup paths for encryption, and sent victim metadata to a command-and-control endpoint before dropping a ransom note tied to the email main@paradisenewgenshinimpact.top and a Bitcoin wallet. Defenders were urged to patch exposed remote-access software and maintain endpoint protections to reduce the risk of Paradise deployment.

Jun 15
The Record Media

Source code for Paradise ransomware leaked on hacking forums | The Record from Recorded Future News

Mar 26
Palo Alto Networks Unit 42

Threat Assessment: Matrix Ransomware

Matrix ransomware has targeted small- to medium-sized organizations in multiple countries since its public emergence in 2016, with its delivery methods shifting over time from spam emails, malicious Windows shortcut files, and the RIG exploit kit to the brute forcing of weak Remote Desktop Protocol (RDP) credentials. The campaign reflects a broader move toward targeted ransomware intrusions that rely on exposed remote access services rather than mass distribution alone. Once launched, Matrix encrypts local files and network shares, deletes volume shadow copies, disables recovery options, and demands payment in Bitcoin. Operators use a variable ransom model in which victims are told to make contact and provide sample files for decryption so the attackers can assess payment demands; known variants use multiple file extensions, including the Fox strain that appends .FOX to encrypted files.

Nov 11
Register Security

If it sounds too good to be true, it most likely is: Nobody can decrypt the Dharma ransomware

Security researchers said companies claiming to decrypt files locked by Dharma/Crisis ransomware are not defeating the malware’s encryption, which experts described as effectively unbreakable without a flaw or the criminals’ private key. An investigation by Emsisoft and outside researchers challenged Australian firm Fast Data Recovery after it advertised a high chance of recovering Dharma-encrypted files and claimed it could reverse engineer decryption keys, despite specialists including Brett Callow, Michael Gillespie, Bill Siegel, and Fabian Wosar saying no such capability is known to exist. Separate research by Check Point found that Russian service Dr. Shifro allegedly operated as a broker between victims and ransomware operators, buying decryption keys at a discount and reselling recovery at a markup rather than performing true cryptographic recovery. In a sting operation, Check Point observed the service requesting encrypted samples and then contacting the attacker-side email to negotiate key purchases; the researchers linked the activity to iharauch@gmail.com and identified a likely operator in Moscow, estimating profits of about $1,350 per victim and potentially hundreds of thousands of dollars overall.

Dec 2
Checkpoint Research

The Ransomware Doctor Without a Cure - Check Point Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.