Karma

Description

Karma is a ransomware group first observed in November 2021, operating a double-extortion model that combines data theft with encryption. The group primarily targets enterprises across various sectors, including healthcare, manufacturing, and technology, with confirmed victims in North America, Europe, and Asia. Karma is believed to be a rebrand or evolution of the FiveHands ransomware, itself derived from the earlier HelloKitty codebase, based on overlaps in encryption methods and ransom portal design. The ransomware appends the .KARMA extension to encrypted files and leaves ransom notes named KARMA-README.txt, directing victims to a Tor-based negotiation site. Initial access is typically obtained through compromised VPN credentials, exploitation of vulnerabilities in public-facing systems, and use of access brokers. Unlike some groups, Karma operators claim to avoid encrypting systems in healthcare emergency services, instead focusing on exfiltration and extortion.

External Analysis
https://blog.cyble.com/2021/08/24/a-deep-dive-analysis-of-karma-ransomware/
https://blogs.blackberry.com/en/2021/11/threat-thursday-karma-ransomware
https://news.sophos.com/en-us/2022/02/28/conti-and-karma-actors-attack-healthcare-provider-at-same-time-through-proxyshell-exploits/?cmp=30728
https://news.sophos.com/en-us/2022/03/17/the-ransomware-threat-intelligence-center/
https://www.sentinelone.com/labs/karma-ransomware-an-emerging-threat-with-a-hint-of-nemty-pedigree/
https://www.sentinelone.com/labs/nokoyawa-ransomware-new-karma-nemty-variant-wears-thin-disguise/
https://www.symantec.broadcom.com/hubfs/SED/SED_Threat_Hunter_Reports_Alerts/SED_FY22Q2_SES_Ransomware-Threat-Landscape_WP.pdf
https://www.youtube.com/watch?v=hgz5gZB3DxE
Urls
Screen
http://3nvzqyo6l4wkrzumzu5aod7zbosq4ipgf7ifgj3hsvbcr5vcasordvqd.onion
File servers
Screen
Chat servers
Screen
Admin servers
Screen

Posts

Date Title Description Screen
2021-10-04
Our first post
2021-10-04
Saurer. Part 1.
2021-10-04
Align Technology. Part 1.
2021-10-04
The next leak will be of a multi billion dollar cosmetics and fragrance company.
2021-10-04
Align Technology. Part 2.
2021-10-04
SI Group. Part 1.
2021-10-04
YASH Technologies. Part 1.