×
GreekEnglish

×
  • Politics
  • Diaspora
  • World
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Cooking
Wednesday
11
Feb 2026
weather symbol
Athens 15°C
  • Home
  • Politics
  • Economy
  • World
  • Diaspora
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Mediterranean Cooking
  • Weather
Contact follow Protothema:
Powered by Cloudevo
> technology

New Cmb Dharma ransomware variant discovered

How to protect yourself from the Dharma Cmb Ransomware

Newsroom October 12 01:45

On Thursday a new variant of the Dharma Ransomware was discovered that appends the .cmb extension to encrypted files.

The Cmb variant of the Dharma Ransomware was first discovered by Michael Gillespie when he noticed samples uploaded to ID Ransomware, After tweeting about it, Jakub Kroustek replied with a hash to the sample.

Unfortunately, there is no way to decrypt files infected with the Dharma Cmb Ransomware variant for free. For those who wish to discuss this ransomware or receive support, you can use the dedicated Dharma Ransomware Support & Help topic.

Distributed through hacked Remote Desktop Services

The Dharma Ransomware family, including this Cmb variant, is installed manually by attackers hacking into computers over Remote Desktop Protocol Services (RDP). The attackers will scan the Internet for computers running RDP, usually on TCP port 3389, and then attempt to brute force the password for the computer.

Once they gain access to the computer they will install the ransomware and let it encrypt the computer. If the attackers are able to encrypt other computers on the network, they will attempt to do so as well.

>Related articles

What qualities does a good astronaut have for the mission to the Moon? The requirements of NASA

Espionage in space too: Russian vehicles have allegedly intercepted communications from critical European satellites

Research reveals that the inhabitants of Messa Mani constitute a unique genetic “island” in Europe

How the CMB Dharma Ransomware encrypts a computer

When the Cmb ransomware variant is installed, it will scan a computer for files and encrypt them. When encrypting a file it will append an extension in the format of .id-[id].[email].cmb. For example, a file called test.jpg would be encrypted and renamed to test.jpg.id-BCBEF350.[paymentbtc@firemail.cc].cmb.

It should be noted that this ransomware will encrypt mapped network drives, shared virtual machine host drives,  and unmapped network shares. So it is important to make sure your network’s shares are locked down so that only those who actually need access have permission.

Read more HERE

Ask me anything

Explore related questions

#ransomware#science#technology#variant
> More technology

Follow en.protothema.gr on Google News and be the first to know all the news

See all the latest News from Greece and the World, the moment they happen, at en.protothema.gr

> Latest Stories

Greece deports activist of Pontic Greek descent Yiannis-Vasilis Yailali for the second time

February 11, 2026

Seven agreements signed at the 6th Greece-Turkey high-level Cooperation Council

February 11, 2026

European Parliament adopts sweeping proposals to address housing crisis

February 11, 2026

Instagram chief to testify in court over youth social media addiction

February 11, 2026

At Votanikos, Alafouzos, Hatzidakis, and Doukas: “Panathinaikos’ stadium is progressing according to schedule”

February 11, 2026

NATO launches Arctic Sentry to strengthen its presence in the Arctic

February 11, 2026

Accessibility problems for people with disabilities at banks and ATMs — Letter to the Hellenic Bankers Association

February 11, 2026

Chaos and violent brawling among MPs in the Turkish parliament during the swearing-in of the new Justice and Interior ministers

February 11, 2026
All News

> Greece

Greece deports activist of Pontic Greek descent Yiannis-Vasilis Yailali for the second time

Asylum request rejected due to alleged war crime charges – he denies the accusations

February 11, 2026

Accessibility problems for people with disabilities at banks and ATMs — Letter to the Hellenic Bankers Association

February 11, 2026

Weather Bulletin from the Hellenic National Meteorological Service (HNMS) for a 48-hour double storm starting tonight – The 11 regions that will be hit

February 11, 2026

The 8 hours of testimony by the Wing Commander spy: Approached via LinkedIn, named three individuals

February 11, 2026

Three names provided by the Wing Commander who spied for China: The private companies, “Steven” & his career plans

February 11, 2026
Homepage
PERSONAL DATA PROTECTION POLICY COOKIES POLICY TERM OF USE
Powered by Cloudevo
Copyright © 2026 Πρώτο Θέμα