Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
Dharma is a ransomware family, commonly referenced as a ransomware-as-a-service (RaaS) variant and frequently discussed alongside Phobos due to their similarity and shared affiliate-style ecosystem.
Profile source: Mallory opens in a new tabDharma
Dharma is a ransomware family, commonly referenced as a ransomware-as-a-service (RaaS) variant and frequently discussed alongside Phobos due to their similarity and shared affiliate-style ecosystem. The provided content places Dharma among long-running ransomware families that remained active or widely observed through at least 2021–2023, and notes that affiliates often move between multiple RaaS programs rather than remaining loyal to one brand. Reporting cited in the content also links some activity around 8base to former Dharma and Phobos affiliates.
Operationally, the content associates Dharma with campaigns that begin through phishing emails or compromised credentials. It is characterized as affecting smaller organizations in some reporting, including “spray and pray” style attacks and attacks against small companies with exposed RDP, while other reporting notes its presence among top ransomware variants observed in incident-response datasets. The content also states Dharma was among variants associated with re-extortion, where victims may be pressured for additional payment after an initial ransom.
A recurring theme in the source material is Dharma operators’ abuse of legitimate, often digitally signed administrative or troubleshooting tools to disable defenses before ransomware deployment. Tools explicitly mentioned in Dharma-linked campaigns include IOBit Unlocker, Process Hacker, PowerRun, YDArk, Mimikatz, and Unlock_IT. According to the cited reporting, these tools were used to kill antivirus or EDR processes, gain SYSTEM- or kernel-level access, steal credentials, and erase logs or forensic traces. More generally, the content ties Dharma to defense-impairment behavior such as abusing legitimate rootkit-removal kits and low-level tools to disable security products.
The content also includes ecosystem and law-enforcement context. Ukraine’s Cyber Police reportedly detained suspects in November 2022 in connection with LockerGoga, MegaCortex, Hive, and Dharma ransomware attacks, and later investigations and arrests in Ukraine were again described as involving the Dharma ransomware family. Financial reporting cited in the content includes Dharma in ransomware payment analyses, with one Chainalysis dataset characterizing Dharma as a low-level RaaS strain used against smaller targets and listing very small average and median payment sizes. Only high-confidence information directly stated in the content is included here.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 MITRE ATT&CK
Reporting
This tactic was observed in campaigns involving LockBit Black 3.0 and Dharma ransomware.
IOBit Unlocker has been used in Dharma campaigns.
Seqrite researchers identified this growing pattern and noted that the abuse of legitimate low-level tools has become a defining feature of today’s ransomware campaigns — from LockBit 3.0 and BlackCat to Dharma, Phobos, and MedusaLocker.
...existing ransomware families such as LockBit, CryLock, Xorist, Proton, GlobeImposter, Chaos, Makop, MedusaLocker, Djvu, Dharma, and more.
In November 2022, Ukraine's Cyber Police detained five suspects involved in LockerGoga, MegaCortex, Hive, and Dharma ransomware attacks.
Authorities said they were able to trace the suspect following a forensic analysis of equipment seized in a previous raid that took place in November 2023 targeting members of the LockerGoga, MegaCortex, and Dharma ransomware families.
This operation led to the identification, seizure of devices, and arrest of multiple cybercriminals residing in Ukraine for their involvement in the LockerGoga, MegaCortex, Hive, and Dharma ransomware families.
...8base ... linked either to former Dharma and Phobos affiliates...
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.