Netskope Threat Labs

Crysis

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Crysis (a.k.a. Arena, Dharma, Wadhrama, ncov) is a ransomware variant that cyberattackers typically install after gaining initial access through exposed remote desktop services. It encrypts files with strong cryptography and appends extensions that name the family and the victim's identifier, and its operators have sold access to thousands of small and mid sized organizations. The family's many rebrands complicate reporting, but the underlying code and tactics have stayed consistent for years.

First seen
February 2022
Last seen
October 2026
Alert Name
Dropped:Generic.Ransom.Crysis.9FABBDCF
Gen:Variant.Ransom.Crysis.10
Gen:Variant.Ransom.Crysis.104
Gen:Variant.Ransom.Crysis.74
Gen:Variant.Ransom.Crysis.83
Trojan.Ransom.Crysis.E
Trojan.Ransom.Crysis.H
Win32.Ransomware.Crysis
Win32.Trojan.Crysis