×
GreekEnglish

×
  • Politics
  • Diaspora
  • World
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Cooking
Friday
19
Dec 2025
weather symbol
Athens 12°C
  • Home
  • Politics
  • Economy
  • World
  • Diaspora
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Mediterranean Cooking
  • Weather
Contact follow Protothema:
Powered by Cloudevo
> technology

New Cmb Dharma ransomware variant discovered

How to protect yourself from the Dharma Cmb Ransomware

Newsroom October 12 01:45

On Thursday a new variant of the Dharma Ransomware was discovered that appends the .cmb extension to encrypted files.

The Cmb variant of the Dharma Ransomware was first discovered by Michael Gillespie when he noticed samples uploaded to ID Ransomware, After tweeting about it, Jakub Kroustek replied with a hash to the sample.

Unfortunately, there is no way to decrypt files infected with the Dharma Cmb Ransomware variant for free. For those who wish to discuss this ransomware or receive support, you can use the dedicated Dharma Ransomware Support & Help topic.

Distributed through hacked Remote Desktop Services

The Dharma Ransomware family, including this Cmb variant, is installed manually by attackers hacking into computers over Remote Desktop Protocol Services (RDP). The attackers will scan the Internet for computers running RDP, usually on TCP port 3389, and then attempt to brute force the password for the computer.

Once they gain access to the computer they will install the ransomware and let it encrypt the computer. If the attackers are able to encrypt other computers on the network, they will attempt to do so as well.

>Related articles

Research: The BBC’s “first Black Briton” from the Roman era was ultimately…white and originated from southern England

The Greeks of Silicon Valley

Voyager 1 ready to make history again: in 2026 it will reach a distance of “one light-day” from Earth

How the CMB Dharma Ransomware encrypts a computer

When the Cmb ransomware variant is installed, it will scan a computer for files and encrypt them. When encrypting a file it will append an extension in the format of .id-[id].[email].cmb. For example, a file called test.jpg would be encrypted and renamed to test.jpg.id-BCBEF350.[paymentbtc@firemail.cc].cmb.

It should be noted that this ransomware will encrypt mapped network drives, shared virtual machine host drives,  and unmapped network shares. So it is important to make sure your network’s shares are locked down so that only those who actually need access have permission.

Read more HERE

Ask me anything

Explore related questions

#ransomware#science#technology#variant
> More technology

Follow en.protothema.gr on Google News and be the first to know all the news

See all the latest News from Greece and the World, the moment they happen, at en.protothema.gr

> Latest Stories

British Museum: Loans of up to 3 years are its new model for antiquities removed from other countries – What it plans to do with the Parthenon Sculptures

December 19, 2025

“Flying” Santas filled the children in the oncology department of Pagni with joy, watch video

December 19, 2025

Embraer’s Eve made the maiden flight of the “flying car,” having received over 3,000 pre-orders

December 19, 2025

In the mountain forests of the Peloponnese, Greek fir trees are dying en masse without being burned

December 19, 2025

Rubio on the Ukraine peace talks: ‘There is progress, but we have a long way to go’

December 19, 2025

Nick Rainer had been diagnosed with schizophrenia weeks before murdering his parents

December 19, 2025

5-month-old baby found dead in Attica: “We woke up and found her cold,” says the mother

December 19, 2025

The Trump administration is preparing to release hundreds of thousands of documents in the Epstein case

December 19, 2025
All News

> World

Embraer’s Eve made the maiden flight of the “flying car,” having received over 3,000 pre-orders

The company aims for certification in 2026 and first deliveries and entry into service in 2027

December 19, 2025

Rubio on the Ukraine peace talks: ‘There is progress, but we have a long way to go’

December 19, 2025

Nick Rainer had been diagnosed with schizophrenia weeks before murdering his parents

December 19, 2025

The Trump administration is preparing to release hundreds of thousands of documents in the Epstein case

December 19, 2025

No more famine in Gaza, but food insecurity remains, says UN

December 19, 2025
Homepage
PERSONAL DATA PROTECTION POLICY COOKIES POLICY TERM OF USE
Powered by Cloudevo
Copyright © 2025 Πρώτο Θέμα