×
GreekEnglish

×
  • Politics
  • Diaspora
  • World
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Cooking
Friday
16
Jan 2026
weather symbol
Athens 16°C
  • Home
  • Politics
  • Economy
  • World
  • Diaspora
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Mediterranean Cooking
  • Weather
Contact follow Protothema:
Powered by Cloudevo
> technology

New Cmb Dharma ransomware variant discovered

How to protect yourself from the Dharma Cmb Ransomware

Newsroom October 12 01:45

On Thursday a new variant of the Dharma Ransomware was discovered that appends the .cmb extension to encrypted files.

The Cmb variant of the Dharma Ransomware was first discovered by Michael Gillespie when he noticed samples uploaded to ID Ransomware, After tweeting about it, Jakub Kroustek replied with a hash to the sample.

Unfortunately, there is no way to decrypt files infected with the Dharma Cmb Ransomware variant for free. For those who wish to discuss this ransomware or receive support, you can use the dedicated Dharma Ransomware Support & Help topic.

Distributed through hacked Remote Desktop Services

The Dharma Ransomware family, including this Cmb variant, is installed manually by attackers hacking into computers over Remote Desktop Protocol Services (RDP). The attackers will scan the Internet for computers running RDP, usually on TCP port 3389, and then attempt to brute force the password for the computer.

Once they gain access to the computer they will install the ransomware and let it encrypt the computer. If the attackers are able to encrypt other computers on the network, they will attempt to do so as well.

>Related articles

Elon Musk: Don’t save for retirement – It won’t matter

Research: The BBC’s “first Black Briton” from the Roman era was ultimately…white and originated from southern England

The Greeks of Silicon Valley

How the CMB Dharma Ransomware encrypts a computer

When the Cmb ransomware variant is installed, it will scan a computer for files and encrypt them. When encrypting a file it will append an extension in the format of .id-[id].[email].cmb. For example, a file called test.jpg would be encrypted and renamed to test.jpg.id-BCBEF350.[[email protected]].cmb.

It should be noted that this ransomware will encrypt mapped network drives, shared virtual machine host drives,  and unmapped network shares. So it is important to make sure your network’s shares are locked down so that only those who actually need access have permission.

Read more HERE

Ask me anything

Explore related questions

#ransomware#science#technology#variant
> More technology

Follow en.protothema.gr on Google News and be the first to know all the news

See all the latest News from Greece and the World, the moment they happen, at en.protothema.gr

> Latest Stories

Study in Greece: International students apply for a place in Greek universities through a single platform

January 16, 2026

Users on X respond to Rama’s comments on whether modern Greeks are descendants of the ancient Greeks

January 16, 2026

Cycladic Identity Initiative launches fourth funding phase to preserve the Cultural and Natural Heritage of the Cyclades

January 16, 2026

Cold wave from Ukraine to hit Greece: Temperatures drop to 10°C, Gale-Force winds in the Aegean and Ionian Seas

January 16, 2026

The billionaire behind Trump’s Greenland decisions convinced him that the U.S. should acquire it

January 16, 2026

A treat for readers: Dior, bags, and literature

January 16, 2026

Greek firms secure key roles in Libya’s reconstruction

January 16, 2026

Why Trump hasn’t “pressed the button” to attack Iran: White House and allies doubt it will weaken the Iranian regime

January 16, 2026
All News

> Culture

Cycladic Identity Initiative launches fourth funding phase to preserve the Cultural and Natural Heritage of the Cyclades

Supporting the preservation of Cycladic culture and biodiversity — The Museum of Cycladic Art invites nonprofit organizations to apply for the fourth phase of its Cycladic Identity funding program through February 20, 2026

January 16, 2026

Grief in Crete for the loss of Yannis Xylouris

January 15, 2026

“A Picasso for 100 euros” — Christie’s for a million-euro painting

January 15, 2026

New cultural route at the Acropolis highlights the historic Koili Odos

January 15, 2026

“All cash”: Netflix is preparing a strategic move to accelerate its $83 billion deal with Warner Bros.

January 14, 2026
Homepage
PERSONAL DATA PROTECTION POLICY COOKIES POLICY TERM OF USE
Powered by Cloudevo
Copyright © 2026 Πρώτο Θέμα