Skip to content
  • Active
  • Severity: High
  • Ransomware
  • Windows
  • Verified · Jun 2020

How to remove Kharma ransomware

A step-by-step removal guide for affected devices. Follow the verified procedure below — most readers complete it in under 10 minutes.

Jake Doevan · Computer technology expert

Kharma ransomware is a file locking virus that threatens to delete the key to the locked files on the host machine after seven days

Kharma ransomware

Kharma ransomware is a file locking malware that was first spotted in the wild in November 2019 and is a part of the Dharma virus family. The goal of this virus is to make users pay a ransom in Bitcoin or another cryptocurrency for the encrypted data, which is locked with the RSA encryption algorithm,[1] and each of the files is appended with .kharma extension. To let victims know about what happened to their data and how they can recover them, malicious actors behind Kharma ransomware also incorporate two ransom notes – Info.hta and RETURN FILES.txt.

Both notes serve as a message from Kharma virus authors, as users are explained that they need to contact crooks via teammarcy10@cock.li for further instructions. While there is no decryptor for this malware yet, users should avoid reaching cybercriminals as there is a chance to lose not only the encrypted files but also the money.[2] While chances are low, there are other methods that could help victims to recover their data after Kharma ransomware removal.

Name Kharma ransomware
Type Cryptovirus, file locking malware
Malware family The virus belongs to Dharma/Crysis ransomware family, which is among the most prominent ransomware infections in the wild
Infection Ransomware uses several methods for propagation, including infected installers (such as crack tool KMSpico) malicious spam email attachments, weak RDP connections, etc.
Encryption algorithm The virus uses the RSA encryption algorithm to lock all personal data on the device
File extension Each of the files is appended with .[teammarcy10@cock.li].kharma file extension. For example, a picture.jpg is turned into picture.jpg.[teammarcy10@cock.li].kharma and is no longer accessible. Malware skips .exe, .sys and few other file formats, however
Ransom notes  Info.hta (titled “eammarcy10@cock.li” once opened) and RETURN FILES.txt are dropped into each of the affected files' folders – both serve as messages from malicious actors and explain to users how to proceed next
Contact emails  Users can write to teammarcy10@cock.li or justbtcwillhelpu@firemail.cc emails to contact cybercriminals
File decryption  Currently, there is no Kharma ransomware decryptor available. However, users can restore all files from backups (if available) or try using third-party recovery tools – we provide the instructions below
Malware removal  Best way to eliminate the virus is to access Safe Mode with Networking and then scanning the machine with reputable anti-malware software 
Recovery After malware elimination, we suggest scanning the machine with FortectIntego to fix virus damage and restore Windows registry files

Dharma is an old ransomware family – it was first established in 2016, and since then, dozens of variants were released. Mostly, the malware targets organizations,[3] although regular computer users can also easily get infected with the Kharma virus or another variant of malware.

Kharma ransomware developers use several infection methods for malware propagation, including:

  • Poorly protected RDP conections
  • Spam email attachments
  • Malicious executables, such as KMSpico (it is a crack tool used to unlock full version of MS Office or Windows)
  • Malicious ads.

Once inside the system, Kharma ransomware starts system modification in order to prepare it for the file encryption process. It drops several files on the OS, modifies Windows registry, deletes Shadow Volume Copies, accesses various Windows processes (such as lsass.exe or vssadmin.exe), loads new modules, etc. Once the preparations are complete, Kharma ransomware begins to scan the machine for files to encrypt.

Kharma ransomware encrypts the most popular file types that are used in corporations and by home users, including .pdf, .doc., .txt, .jpg, .mp3, .mpg, .sql, etc. At that point, users lose access to their files, as a strong cryptographic algorithm is applied to them. To retrieve access to data, victims need to acquire a key that is sent to hackers' Command & Control server.[4] According to cybercriminals behind Kharma, users should not tamper with the encrypted data, as they might lose them completely. Besides, in the ransom note, they also mentioned that the decryption key would be deleted after seven days of the infection. 

Kharma ransomware virus

Besides the Info.hta file, users can also access a brief version of the note which states:

All your data is encrypted!
for return write to mail:
teammarcy10@cock.li or justbtcwillhelpu@firemail.cc

Paying ransom is extremely risky, as hackers might never send the required decryption software and simply keep the money. Therefore, rather backup all the encrypted data, remove Kharma ransomware with anti-malware that can recognize the malware, attempt to recover files with the help of our instructions below, and, finally, scan your machine with FortectIntego to ensure a swift recovery after the infection.

Ransomware developers use multiple methods to deliver the malicious payloads

Using several different methods for ransomware delivery simply ensures that more people will get infected, consequently increasing the chances of the ransom being paid. As previously mentioned, users get infected with Dharma variants after downloading a malicious version of a crack tool KMSpico or similar software and run it on their machines in order to bypass the licensing process of MS Office or Windows OS. Pirating software is not only illegal but often brings to malware infections. While most of the users are aware of the risk, they are still willing to proceed with downloading and running software cracks. Therefore, stay away from illegal software installers and key generators/cracks, as these tools are likely to be infected with a secondary payload, such as ransomware.

Security researchers[5] also warn that the built-in Windows feature like Remote Desktop connection can also be used to insert the malware manually. Most of the time, hackers can the internet for poorly protected RDPs, apply thousands of passwords with the help of automated software, brute-forcing the access to the machine, and install the payload manually. To avoid such consequences, users should never use a default TCP port and use complex passwords for these connections.

Kharma ransomware encrypted files

Spam email attachments with embedded malicious macros are also one of the most used ways to propagate ransomware. Crooks compile a phishing email that prompts users to click on a fake .pdf, .doc, .txt, or similar file, which executes commands that lead to download and installation of malware. When dealing with daily emails, make sure that they come from legitimate sources and never allow the document to run macro commands.

Finally, it is also vital to backup all relevant files on a regular basis, ensure Windows is up-to-date, run a comprehensive security solution, and exercise general safe internet browsing practices.

Get rid of Kharma ransomware before trying file restoration process

While there is a way to remove Kharma ransomware manually, it is almost impossible to achieve for regular computer users, as cryptoviruses change the system drastically, dropping multiple files, spawning new processes, etc. Therefore, it is best to get rid of malware and all its components via the anti-malware software scan. In some cases, the virus might interfere with the operation of the security tool – simply access Safe Mode with Networking and perform a full system scan from there. Note, you should backup all the locked files before you eliminate the Kharma virus, as the process might permanently damage the data.

After Kharma ransomware removal is complete and files are backed up, you can try to recover the encrypted data. As previously mentioned, there is no Kharma decryptor available, so the only way is to retrieve files from backups. In case no backups are available, you can try using third-party recovery software or Windows Previous Versions feature as per instructions below.

Did this guide help?

Be the first to comment

Spyware News
Privacy preferences

We use cookies to improve your experience and analyze traffic. Some cookies enable embedded content like videos and social posts. Choose what you allow — you can change this anytime.