×
GreekEnglish

×
  • Politics
  • Diaspora
  • World
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Cooking
Sunday
18
Jan 2026
weather symbol
Athens 7°C
  • Home
  • Politics
  • Economy
  • World
  • Diaspora
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Mediterranean Cooking
  • Weather
Contact follow Protothema:
Powered by Cloudevo
> technology

New Cmb Dharma ransomware variant discovered

How to protect yourself from the Dharma Cmb Ransomware

Newsroom October 12 01:45

On Thursday a new variant of the Dharma Ransomware was discovered that appends the .cmb extension to encrypted files.

The Cmb variant of the Dharma Ransomware was first discovered by Michael Gillespie when he noticed samples uploaded to ID Ransomware, After tweeting about it, Jakub Kroustek replied with a hash to the sample.

Unfortunately, there is no way to decrypt files infected with the Dharma Cmb Ransomware variant for free. For those who wish to discuss this ransomware or receive support, you can use the dedicated Dharma Ransomware Support & Help topic.

Distributed through hacked Remote Desktop Services

The Dharma Ransomware family, including this Cmb variant, is installed manually by attackers hacking into computers over Remote Desktop Protocol Services (RDP). The attackers will scan the Internet for computers running RDP, usually on TCP port 3389, and then attempt to brute force the password for the computer.

Once they gain access to the computer they will install the ransomware and let it encrypt the computer. If the attackers are able to encrypt other computers on the network, they will attempt to do so as well.

>Related articles

Elon Musk: Don’t save for retirement – It won’t matter

Research: The BBC’s “first Black Briton” from the Roman era was ultimately…white and originated from southern England

The Greeks of Silicon Valley

How the CMB Dharma Ransomware encrypts a computer

When the Cmb ransomware variant is installed, it will scan a computer for files and encrypt them. When encrypting a file it will append an extension in the format of .id-[id].[email].cmb. For example, a file called test.jpg would be encrypted and renamed to test.jpg.id-BCBEF350.[paymentbtc@firemail.cc].cmb.

It should be noted that this ransomware will encrypt mapped network drives, shared virtual machine host drives,  and unmapped network shares. So it is important to make sure your network’s shares are locked down so that only those who actually need access have permission.

Read more HERE

Ask me anything

Explore related questions

#ransomware#science#technology#variant
> More technology

Follow en.protothema.gr on Google News and be the first to know all the news

See all the latest News from Greece and the World, the moment they happen, at en.protothema.gr

> Latest Stories

Politico: Europe for the first time considers tough response to Trump on Greenland tariffs, what is the Anti-Brexit Act

January 18, 2026

The backstory behind Trump’s decision not to attack Iran: The camps in the White House, the SMS from Tehran, and the calls from Arab allies

January 18, 2026

Mitsotakis: Greece will not be challenged by anyone with the Belharra frigates – Our goal is to support farmers with transparent subsidies

January 18, 2026

Akylas receives rave reviews for his Eurovision 2026 Greek final entry: “We might actually win with this little gem,” Fans write

January 18, 2026

What Trump is seeking with the extra tariffs on eight European countries for Greenland, the trade deal with the EU is in the air

January 18, 2026

The global era of Messinia: How the film Odyssey and the lists of major media praise it for 2026

January 18, 2026

Greek exports broke records with a record 37 billion euros

January 18, 2026

Sakkari delivers the ‘point of the year’ as she advances at the Australian Open

January 18, 2026
All News

> Diaspora

St Nicholas Greek Orthodox Church: Feeding the Homeless – Sunday, January 18

Sunday, January 18 Meal Prep: 6pm – 7:30pm >Related articles Sports broadcasts: Where to watch the Conference League play-off draw, the derby in volleyball, and the EuroLeagueThe ordeal of a 28-year-old Greek man in Australia: He went on holiday to visit relatives, was injured at a beach, and is at risk of quadriplegiaSt Nicholas Greek […]

January 12, 2026

Registrations open for 2026 Greek Community Cup Women’s Tournament

January 7, 2026

Vasilopita and New Year Traditions, from antiquity to the present day

January 5, 2026

Light and Water at Theophany and in Ancient Greece

January 2, 2026

St. Nicholas Greek Orthodox Church: A final Stewardship appeal before year’s end

December 31, 2025
Homepage
PERSONAL DATA PROTECTION POLICY COOKIES POLICY TERM OF USE
Powered by Cloudevo
Copyright © 2026 Πρώτο Θέμα