Skip to content

Karma

Karma is a ransomware operation linked in public reporting with the wider Nemty, Nokoyawa, and JSWORM ransomware ecosystem.

Profile source: Ransomware.live opens in a new tab

Karma

Family profile

Karma is a ransomware operation linked in public reporting with the wider Nemty, Nokoyawa, and JSWORM ransomware ecosystem. This profile excludes the unrelated iOS exploitation tool and wireless attack technique that share the Karma name.

Operational record

1
YARA rules
1
Ransom notes
2
Leak sites
1 available

MITRE ATT&CK

Karma in ATT&CK

63 distinct techniques

Techniques

63 techniques
T1078 Valid Accounts T1078.002 Valid Accounts: Domain Accounts T1078.004 Valid Accounts: Cloud Accounts T1133 External Remote Services T1190 Exploit Public-Facing Application T1199 Trusted Relationship T1566 Phishing T1047 Windows Management Instrumentation T1059.001 Command and Scripting Interpreter: PowerShell T1059.006 Command and Scripting Interpreter: Python T1072 Software Deployment Tools T1204.002 User Execution: Malicious File T1651 Cloud Administration Command T1098 Account Manipulation T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1484.001 Domain or Tenant Policy Modification: Group Policy Modification T1027.015 Obfuscated Files or Information: Compression T1036.004 Masquerading: Masquerade Task or Service T1036.005 Masquerading: Match Legitimate Resource Name or Location T1564.003 Hide Artifacts: Hidden Window T1679 Selective Exclusion T1684.001 Social Engineering: Impersonation T1003.001 OS Credential Dumping: LSASS Memory T1110 Brute Force T1110.001 Brute Force: Password Guessing T1110.004 Brute Force: Credential Stuffing T1552.002 Unsecured Credentials: Credentials in Registry T1082 System Information Discovery T1087.002 Account Discovery: Domain Account T1021.001 Remote Services: Remote Desktop Protocol T1005 Data from Local System T1074 Data Staged T1113 Screen Capture T1114.002 Email Collection: Remote Email Collection T1119 Automated Collection T1123 Audio Capture T1125 Video Capture T1213.002 Data from Information Repositories: Sharepoint T1560.001 Archive Collected Data: Archive via Utility T1041 Exfiltration Over C2 Channel T1071.001 Application Layer Protocol: Web Protocols T1102 Web Service T1105 Ingress Tool Transfer T1219.002 Remote Access Tools: Remote Desktop Software T1572 Protocol Tunneling T1485 Data Destruction T1486 Data Encrypted for Impact T1490 Inhibit System Recovery T1561.001 Disk Wipe: Disk Content Wipe T1561.002 Disk Wipe: Disk Structure Wipe T1657 Financial Theft T1583.001 Acquire Infrastructure: Domains T1583.003 Acquire Infrastructure: Virtual Private Server T1583.004 Acquire Infrastructure: Server T1583.006 Acquire Infrastructure: Web Services T1585.001 Establish Accounts: Social Media Accounts T1585.002 Establish Accounts: Email Accounts T1587.001 Develop Capabilities: Malware T1588.001 Obtain Capabilities: Malware T1588.002 Obtain Capabilities: Tool T1589 Gather Victim Identity Information T1595.002 Active Scanning: Vulnerability Scanning T1686.003 Disable or Modify System Firewall: Windows Host Firewall

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.