Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Karma

| RaaS

Karma is a ransomware group first observed in mid-2021, part of a lineage tracing back through Nefilim and FiveHands, operating double-extortion attacks against enterprises in healthcare, manufacturing, and technology; the group was managed by threat actor "farnetwork" who ran multiple RaaS programs across related strains. Platforms: Windows and Linux
Extension(s): KARMA

Victims
7
 
First Discovered
2021-10-04
victim
Last Discovered
2021-10-04
victim
Inactive Since
4yrs
more than
Avg Delay
N/A
attack→claim
Infostealer
N/A
victims with domain
Countries
0
hit
View Victims on World Map View Group Statistics

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Karma Leaks No 2026-07-25T18:25:29 3nvzqyo6l4wkrzumzu5aod7zbosq4ipgf7ifgj3hsvbcr5vcasordvqd.onion
favicon Karma Leaks — Exclusive Leaks & Intelligence No 2026-07-29T08:38:18 2dmzkuruwpmgalhcn26kmvlg37ijqbzqo3orhxwvyf2nf3w4gfq6ikid.onion

Target
Top 5 Activity Sectors
  • Technology 3
  • Manufacturing 2
  • Retail & E-Commerce 1
Top 5 Countries

Heatmap

Ransom Notes (1)

TTPs Matrix (15)
This information is provided by Crocodyli & Ransomware.live
Initial Access Execution Persistence Privilege Escalation Stealth Credential Access Discovery Lateral Movement Collection Exfiltration Command and Control Impact Resource Development Reconnaissance Defense Impairment
Valid Accounts Windows Management Instrumentation Valid Accounts Valid Accounts Obfuscated Files or Information: Compression OS Credential Dumping: LSASS Memory System Information Discovery Remote Services: Remote Desktop Protocol Data from Local System Exfiltration Over C2 Channel Application Layer Protocol: Web Protocols Data Destruction Acquire Infrastructure: Domains Gather Victim Identity Information Domain or Tenant Policy Modification: Group Policy Modification
Valid Accounts: Domain Accounts Command and Scripting Interpreter: PowerShell Valid Accounts: Domain Accounts Valid Accounts: Domain Accounts Masquerading: Masquerade Task or Service Brute Force Account Discovery: Domain Account Software Deployment Tools Data Staged   Web Service Data Encrypted for Impact Acquire Infrastructure: Virtual Private Server Active Scanning: Vulnerability Scanning Disable or Modify System Firewall: Windows Host Firewall
Valid Accounts: Cloud Accounts Command and Scripting Interpreter: Python Valid Accounts: Cloud Accounts Valid Accounts: Cloud Accounts Masquerading: Match Legitimate Resource Name or Location Brute Force: Password Guessing     Screen Capture   Ingress Tool Transfer Inhibit System Recovery Acquire Infrastructure: Server    
External Remote Services Software Deployment Tools Account Manipulation Account Manipulation Valid Accounts Brute Force: Credential Stuffing     Email Collection: Remote Email Collection   Remote Access Tools: Remote Desktop Software Disk Wipe: Disk Content Wipe Acquire Infrastructure: Web Services    
Exploit Public-Facing Application User Execution: Malicious File External Remote Services Domain or Tenant Policy Modification: Group Policy Modification Valid Accounts: Domain Accounts Unsecured Credentials: Credentials in Registry     Automated Collection   Protocol Tunneling Disk Wipe: Disk Structure Wipe Establish Accounts: Social Media Accounts    
Trusted Relationship Cloud Administration Command Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder Valid Accounts: Cloud Accounts       Audio Capture     Financial Theft Establish Accounts: Email Accounts    
Phishing       Hide Artifacts: Hidden Window       Video Capture       Develop Capabilities: Malware    
        Selective Exclusion       Data from Information Repositories: Sharepoint       Obtain Capabilities: Malware    
        Social Engineering: Impersonation       Archive Collected Data: Archive via Utility       Obtain Capabilities: Tool    

YARA Rules (1)

Indicators of Compromise (IoCs) (3)
Email 3
Type IOC
Email kirklord1967@tutanota.com
Email leonardred1989@protonmail.com
Email mikedillov1986@onionmail.org

Victims (7)
Logo
Discovered: 2021-10-04 (4y ago)
No description available
Logo
Discovered: 2021-10-04 (4y ago)
No description available
Logo
Discovered: 2021-10-04 (4y ago)
No description available
Logo
Discovered: 2021-10-04 (4y ago)
No description available
Logo
Discovered: 2021-10-04 (4y ago)
No description available
Logo
Discovered: 2021-10-04 (4y ago)
No description available