Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 8 IP / 3 hostnames
Dharma, also known as CrySiS, is a Windows ransomware family active since 2016 and operated through a ransomware-as-a-service model.
Profile source: Mallory opens in a new tabDharma
Dharma, also known as CrySiS, is a Windows ransomware family active since 2016 and operated through a ransomware-as-a-service model. It has primarily targeted small and medium-sized organizations, including healthcare entities, through affiliate-led intrusions. Common initial-access methods include phishing and malicious spam, as well as manual deployment following compromise of exposed Remote Desktop Protocol services using weak, stolen, or leaked credentials.
Dharma encrypts a broad range of documents, databases, archives, media, source-code files, and files on accessible local, removable, and network-shared storage. Variants use hybrid cryptography, encrypting file content with AES and protecting per-file encryption material with an embedded RSA public key. Encrypted files are renamed with victim- and operator-specific information and a variant-specific extension, and ransom notes direct victims to contact the operators to obtain a decryptor.
Before encryption, Dharma variants commonly stop database-related services, terminate processes that may lock files, and delete Volume Shadow Copies to inhibit recovery. They may establish persistence through Windows autorun mechanisms and Startup locations. Some variants obfuscate embedded strings and dynamically resolve Windows API functions. Dharma has been observed using legitimate software installers as decoys, presenting a benign installation interface while encryption occurs in a separate process. Dharma is generally manually deployed rather than autonomously propagating laterally, although it can encrypt files on network shares reachable from the compromised host.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac d780677e97da00b2b90849741720c1a02e758356630b63242a18074775c69e1c 2373dac86dbe2f62f37a614c7b66646aaab87343e0f3dc77e90cde201e863082 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 6f73f5d8d8e7843414f4af4d1325841cf07dd769e9661462df3368083819a975 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd Exploited software
MITRE ATT&CK
Reporting
Sophos reported that the Dharma ransomware operation, also known as CrySis, continues to profit as a ransomware-as-a-service scheme by targeting small and medium-sized businesses through high-volume intrusions. Investigators said many attacks begin with compromised or poorly secured Remote Desktop Protocol (RDP) access, often using stolen credentials purchased on criminal forums, before affiliates move deeper into victim networks and deploy the ransomware payload. The operation relies on a standardized affiliate toolkit built around a menu-driven PowerShell script, toolbelt.ps1, that automates much of the attack chain for low-skill operators. Sophos said the toolkit combines Windows utilities, legitimate freeware, public exploits, and custom scripts for credential theft with Mimikatz, reconnaissance, Active Directory discovery, lateral movement, antivirus disruption, Tor-based communications, and final encryption, while a two-stage decryption process keeps affiliates dependent on core operators for key retrieval and victim support.
The Paradise ransomware operation, a long-running ransomware-as-a-service family first seen in 2017, drew renewed concern after the source code for its .NET variant was leaked on the Russian-speaking XSS forum. Researchers said the leak included the Paradise builder and a decryption utility, and analysts verified the files as authentic. Although the .NET branch had seen more limited use than the native Paradise version, newly built samples were reportedly being classified as undecryptable, raising the risk that additional threat actors could repurpose the code against home users and small businesses. Subsequent intrusions showed Paradise being deployed through suspected exploitation of outdated AweSun remote-control software, alongside activity involving Sunlogin flaws, Sliver C2, Cobalt Strike, BYOVD tooling, and XMRig. In one analyzed case, the ransomware used RSA-1024 encryption, deleted Volume Shadow Copies, set persistence through a Windows Run key, prioritized database and backup paths for encryption, and sent victim metadata to a command-and-control endpoint before dropping a ransom note tied to the email main@paradisenewgenshinimpact.top and a Bitcoin wallet. Defenders were urged to patch exposed remote-access software and maintain endpoint protections to reduce the risk of Paradise deployment.
Matrix ransomware has targeted small- to medium-sized organizations in multiple countries since its public emergence in 2016, with its delivery methods shifting over time from spam emails, malicious Windows shortcut files, and the RIG exploit kit to the brute forcing of weak Remote Desktop Protocol (RDP) credentials. The campaign reflects a broader move toward targeted ransomware intrusions that rely on exposed remote access services rather than mass distribution alone. Once launched, Matrix encrypts local files and network shares, deletes volume shadow copies, disables recovery options, and demands payment in Bitcoin. Operators use a variable ransom model in which victims are told to make contact and provide sample files for decryption so the attackers can assess payment demands; known variants use multiple file extensions, including the Fox strain that appends .FOX to encrypted files.
Security researchers said companies claiming to decrypt files locked by Dharma/Crisis ransomware are not defeating the malware’s encryption, which experts described as effectively unbreakable without a flaw or the criminals’ private key. An investigation by Emsisoft and outside researchers challenged Australian firm Fast Data Recovery after it advertised a high chance of recovering Dharma-encrypted files and claimed it could reverse engineer decryption keys, despite specialists including Brett Callow, Michael Gillespie, Bill Siegel, and Fabian Wosar saying no such capability is known to exist. Separate research by Check Point found that Russian service Dr. Shifro allegedly operated as a broker between victims and ransomware operators, buying decryption keys at a discount and reselling recovery at a markup rather than performing true cryptographic recovery. In a sting operation, Check Point observed the service requesting encrypted samples and then contacting the attacker-side email to negotiate key purchases; the researchers linked the activity to iharauch@gmail.com and identified a likely operator in Moscow, estimating profits of about $1,350 per victim and potentially hundreds of thousands of dollars overall.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.