SYMBOLCOMMON_NAMEaka. SYNONYMS
win.karma (Back to overview)

Karma

VTCollection    

Ransomware.

References
2022-04-21 ⋅ Sentinel LABS ⋅ Antonis Terefos
Nokoyawa Ransomware | New Karma/Nemty Variant Wears Thin Disguise
Hive Karma Nemty Nokoyawa Ransomware
2022-03-17 ⋅ Sophos ⋅ Tilly Travers
The Ransomware Threat Intelligence Center
ATOMSILO Avaddon AvosLocker BlackKingdom Ransomware BlackMatter Conti Cring DarkSide dearcry Dharma Egregor Entropy Epsilon Red Gandcrab Karma LockBit LockFile Mailto Maze Nefilim RagnarLocker Ragnarok REvil RobinHood Ryuk SamSam Snatch WannaCryptor WastedLocker
2022-03-16 ⋅ Symantec ⋅ Symantec Threat Hunter Team
The Ransomware Threat Landscape: What to Expect in 2022
AvosLocker BlackCat BlackMatter Conti DarkSide DoppelPaymer Emotet Hive Karma Mespinoza Nemty Squirrelwaffle VegaLocker WastedLocker Yanluowang Zeppelin
2022-02-28 ⋅ Sophos ⋅ Sean Gallagher
Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits
Conti Karma
2021-11-22 ⋅ Youtube (OALabs) ⋅ c3rb3ru5d3d53c, Sergei Frankoff
Introduction To Binlex A Binary Trait Lexer Library and Utility - Machine Learning First Steps...
Karma
2021-11-04 ⋅ Blackberry ⋅ BlackBerry Research & Intelligence Team
Threat Thursday: Karma Ransomware
Karma
2021-10-18 ⋅ SentinelOne ⋅ Antonis Terefos
Karma Ransomware | An Emerging Threat With A Hint of Nemty Pedigree
Karma Nemty
2021-08-24 ⋅ cyble ⋅ Cyble
​A Deep-dive Analysis of KARMA Ransomware
Karma
Yara Rules
[TLP:WHITE] win_karma_auto (20260917 | Detects win.karma.)
rule win_karma_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.karma."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.karma"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 56 57 8d0c00 0fb70411 8d5202 668902 }
            // n = 6, score = 100
            //   56                   | push                esi
            //   57                   | push                edi
            //   8d0c00               | lea                 ecx, [eax + eax]
            //   0fb70411             | movzx               eax, word ptr [ecx + edx]
            //   8d5202               | lea                 edx, [edx + 2]
            //   668902               | mov                 word ptr [edx], ax

        $sequence_1 = { 8d8df4fdffff e8???????? ba???????? 8d8df4fdffff e8???????? 8d95f4fdffff b9???????? }
            // n = 7, score = 100
            //   8d8df4fdffff         | lea                 ecx, [ebp - 0x20c]
            //   e8????????           |                     
            //   ba????????           |                     
            //   8d8df4fdffff         | lea                 ecx, [ebp - 0x20c]
            //   e8????????           |                     
            //   8d95f4fdffff         | lea                 edx, [ebp - 0x20c]
            //   b9????????           |                     

        $sequence_2 = { 83c104 83f808 72f2 0f843e010000 8d7e20 33c0 90 }
            // n = 7, score = 100
            //   83c104               | add                 ecx, 4
            //   83f808               | cmp                 eax, 8
            //   72f2                 | jb                  0xfffffff4
            //   0f843e010000         | je                  0x144
            //   8d7e20               | lea                 edi, [esi + 0x20]
            //   33c0                 | xor                 eax, eax
            //   90                   | nop                 

        $sequence_3 = { 0f1148f0 83e901 75e7 8d55e0 }
            // n = 4, score = 100
            //   0f1148f0             | movups              xmmword ptr [eax - 0x10], xmm1
            //   83e901               | sub                 ecx, 1
            //   75e7                 | jne                 0xffffffe9
            //   8d55e0               | lea                 edx, [ebp - 0x20]

        $sequence_4 = { 0f1f00 8d4010 0f104c18f0 0f1040f0 }
            // n = 4, score = 100
            //   0f1f00               | nop                 dword ptr [eax]
            //   8d4010               | lea                 eax, [eax + 0x10]
            //   0f104c18f0           | movups              xmm1, xmmword ptr [eax + ebx - 0x10]
            //   0f1040f0             | movups              xmm0, xmmword ptr [eax - 0x10]

        $sequence_5 = { 7443 0fb71406 2bd1 7509 83c002 66391406 }
            // n = 6, score = 100
            //   7443                 | je                  0x45
            //   0fb71406             | movzx               edx, word ptr [esi + eax]
            //   2bd1                 | sub                 edx, ecx
            //   7509                 | jne                 0xb
            //   83c002               | add                 eax, 2
            //   66391406             | cmp                 word ptr [esi + eax], dx

        $sequence_6 = { e9???????? 7f0c 8b442418 3bf8 0f8224ffffff }
            // n = 5, score = 100
            //   e9????????           |                     
            //   7f0c                 | jg                  0xe
            //   8b442418             | mov                 eax, dword ptr [esp + 0x18]
            //   3bf8                 | cmp                 edi, eax
            //   0f8224ffffff         | jb                  0xffffff2a

        $sequence_7 = { 8d55e0 57 8bca e8???????? 8d4de0 83c404 }
            // n = 6, score = 100
            //   8d55e0               | lea                 edx, [ebp - 0x20]
            //   57                   | push                edi
            //   8bca                 | mov                 ecx, edx
            //   e8????????           |                     
            //   8d4de0               | lea                 ecx, [ebp - 0x20]
            //   83c404               | add                 esp, 4

        $sequence_8 = { 83fe01 751d 8bc6 0f1f440000 837c85e000 7506 }
            // n = 6, score = 100
            //   83fe01               | cmp                 esi, 1
            //   751d                 | jne                 0x1f
            //   8bc6                 | mov                 eax, esi
            //   0f1f440000           | nop                 dword ptr [eax + eax]
            //   837c85e000           | cmp                 dword ptr [ebp + eax*4 - 0x20], 0
            //   7506                 | jne                 8

        $sequence_9 = { 7469 8b01 8b4904 56 33f6 8945ec 894df0 }
            // n = 7, score = 100
            //   7469                 | je                  0x6b
            //   8b01                 | mov                 eax, dword ptr [ecx]
            //   8b4904               | mov                 ecx, dword ptr [ecx + 4]
            //   56                   | push                esi
            //   33f6                 | xor                 esi, esi
            //   8945ec               | mov                 dword ptr [ebp - 0x14], eax
            //   894df0               | mov                 dword ptr [ebp - 0x10], ecx

    condition:
        7 of them and filesize < 49208
}
[TLP:WHITE] win_karma_w0   (20211108 | Detects Karma Ransomware 2021)
import "pe"

rule win_karma_w0 {
    meta:
        author = "Blackberry Threat Research Team"
        description = "Detects Karma Ransomware 2021"
        date = "2021-10"
        license = "This Yara rule is provided under the Apache License 2.0 (https://www.apache.org/licenses/LICENSE-2.0) and open to any user or organization, as long as you use it under this license and ensure originator credit in any derivative to The BlackBerry Research & Intelligence Team"
        source = "https://blogs.blackberry.com/en/2021/11/threat-thursday-karma-ransomware"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.karma"
        malpedia_rule_date = "20211108"
        malpedia_hash = ""
        malpedia_version = "20211108"
        malpedia_license = "Apache License 2.0"
        malpedia_sharing = "TLP:WHITE"
 
    strings:
        $s1 = "WW91ciBuZXR3b3JrIGhhcyBiZWVuIGJyZWFjaGVkIGJ5IEthcm1hIHJhbnNvbXdhcmUgZ3JvdXAu" ascii wide
        $x2 = "crypt32.dll" nocase
        $x3 = "KARMA" ascii wide
        $x4 = "Sleep" nocase                            

    condition:
        //PE File
        uint16(0) == 0x5a4d and
        //Base64 Karma Note
        all of ($s*) and
        //All Strings
        all of ($x*)
}
Download all Yara Rules