Dharma (CrySiS) Ransomware

Description Summary

Dharma (also known as CrySiS) is a long-running ransomware family first observed in 2016 and offered as ransomware-as-a-service. It is deployed almost entirely by hand after brute-forcing or purchasing exposed RDP credentials, and predominantly hits small and mid-sized businesses. Dharma is the direct ancestor of the Phobos family. Master decryption keys for several older variants were leaked, enabling free decryptors.

Threat Actor

RaaS operators (Russian-speaking); manual RDP-based deployment. Direct ancestor of Phobos.

Technical Indicators

Encryption Extension
.dharma / .cezar / .wallet / .[id].[email].<variant>
Encryption Algorithm
AES-256 (CBC, files) + RSA-1024 (key wrapping)
Ransom Note Name
info.txt / Info.hta (auto-run)
Targeted Industries
SMB cross-sector, Healthcare
First Seen
2016
Last Seen
Active (long tail; some master keys leaked)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 2 T1133 External Remote Services (RDP)
T1078 Valid Accounts
Credential Access x 1 T1110 Brute Force
Defense Evasion x 1 T1562.001 Disable or Modify Tools
Impact x 2 T1490 Inhibit System Recovery
T1486 Data Encrypted for Impact