HomeSecurityDharma ransomware source code is being sold on hacking forums

Dharma ransomware source code is being sold on hacking forums

Dharma ransomware hacking forums

The source code of the popular Dharma ransomware was found for sale on two Russian hacking forums over the weekend.

The FBI has stated that Dharma ransomware is the second most profitable ransomware in recent years, having taken more than $24 million from victims between November 2016 and November 2019.

Now, its source code is being sold on hacking forums for just $2,000, which has alarmed security.

Several ransomware experts believe that the sale of the Dharma ransomware code will likely lead to its wider release online . This, in turn, will lead to its wider spread among multiple cybercrime groups . Therefore , will attacks increase.

Experts are concerned because Dharma is an advanced ransomware, created by an experienced malware. Its encryption pattern is very “advanced.”

The only time the ransomware was “decrypted” was when a group of people leaked the master decryption keys. That is, decryption was not possible through some flaw in the encryption standard.

source code

A brief history of Dharma ransomware

Dharma ransomware first appeared under the name CrySiS in the summer of 2016.

CrySis was a Ransomware-as-a-Service (RaaS) business. Their creator CrySiS created a service where customers (other criminal gangs) could create their own versions of ransomware to distribute to victims – typically via spam campaigns, exploit kits, and brute-force attacks.

However, in November 2016, someone leaked the CrySiS decryption key, and CrySiS RaaS resurfaced two weeks later under the name Dharma.

Some Dharma decryption keys were also leaked in March 2017, but the hackers did not change its name this time and continued to operate unmolested, making Dharma Ransomware-as-a-Service one of the most powerful and profitable businesses.

For years, there have been many versions of Dharma, as the ransomware received numerous updates and new clients sought to distribute it across the planet, creating their own unique variants.

Over the past two years, ransomware attacks have become more targeted. Dharma followed this attack pattern.

In the spring of 2019, a new ransomware called Phobos emerged. Security researchers from Coveware and Malwarebytes discovered that Phobos was identical to Dharma ransomware.

However, Dharma continued to be used in its original form. During 2019, attacks were 50-50.

Jakub Kroustek, Avast 's chief security officer , detected three new versions of Dharma ransomware this week alone , meaning that criminal groups are still using it fervently today.

John Fokker, head of research at McAfee, said that the ransomware's source code has been leaked for some time, but has now been posted on more well-known hacking forums.

Fokker now hopes that Dharma's source code will eventually find its way into the hands of researchers, so that a way of decrypting it can be found.

"If we can get the source code, maybe we can find some flaws," Fokker said today.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS