Description Summary
Dharma (also known as CrySiS) is a long-running ransomware family first observed in 2016 and offered as ransomware-as-a-service. It is deployed almost entirely by hand after brute-forcing or purchasing exposed RDP credentials, and predominantly hits small and mid-sized businesses. Dharma is the direct ancestor of the Phobos family. Master decryption keys for several older variants were leaked, enabling free decryptors.
Threat Actor
RaaS operators (Russian-speaking); manual RDP-based deployment. Direct ancestor of Phobos.
Technical Indicators
Encryption Extension
.dharma / .cezar / .wallet / .[id].[email].<variant>
Encryption Algorithm
AES-256 (CBC, files) + RSA-1024 (key wrapping)
Ransom Note Name
info.txt / Info.hta (auto-run)
Targeted Industries
SMB cross-sector, Healthcare
First Seen
2016
Last Seen
Active (long tail; some master keys leaked)
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 2 | T1133 | External Remote Services (RDP) |
| T1078 | Valid Accounts | |
| Credential Access x 1 | T1110 | Brute Force |
| Defense Evasion x 1 | T1562.001 | Disable or Modify Tools |
| Impact x 2 | T1490 | Inhibit System Recovery |
| T1486 | Data Encrypted for Impact |