Dharma Ransomware is a cryptovirus that encrypts user files and demands a ransom in exchange for a decryption key. The malware is manually delivered by attackers who exploit Remote Desktop Protocol (RDP) services via TCP port 3389 and brute force the password to gain access to a computer. It has caused more than $30 million in damages to at least 200 entities!  Dharma Ransomware comes from a family of Ransomware Trojans and is considered one of the oldest and most active types of Ransomware. This family of Ransomware releases a new form quite frequently.

Is my system infected with Dharma Ransomware?

  • A pop-up message stating your data has been encrypted and asking for ransom.

  • Most files won’t open and ask for a password.

  • Files have been renamed with a new extension.

    • .Adobe, .Bip, .Brrr, .Combo, .Java, .Brrr, .Aleta, .Arena, .Gamma, Etc…

  • Applications won’t open.

  • Disabled antivirus software.

  • The system is locked down.

How can you protect yourself from Ransomware?
  • Reliable backups!

  • Be wary of unsolicited attachments, even from people you know!

  • Restrict RDP access – Port 3389

  • Endpoint/network security

  • Windows and security patch updates!

  • Complex passwords

Ransomware Statistics
  • 63% of confirmed data breaches involved leveraging weak, stolen or default passwords and usernames

  • 22% of small businesses breached by Ransomware attacks in 2017 were so badly affected, they could not continue operating

  • 30% of phishing emails were opened and 12% clicked on infected links or attachments

  • Ransomware is costing businesses more than $75 billion per year with a business attacked every 2 minutes on average

  • Global cyber-crime damages predicted to cost $6 trillion by 2021 (Source: Kaspersky)

  • Ransomware attacks have increased by 600% in 2017

