Skip to content

Haron

Haron is a Windows ransomware family that emerged in 2021 and is widely assessed as a Thanos-derived strain written in C# on the .NET framework.

Profile source: Mallory opens in a new tab

Haron

Family profile

Haron is a Windows ransomware family that emerged in 2021 and is widely assessed as a Thanos-derived strain written in C# on the .NET framework. It has also been noted for operational and presentation similarities to Avaddon, including closely matching ransom-note language, negotiation workflows, and leak-site structure, although attribution to Avaddon operators has not been established conclusively. Some reporting has also suggested a possible relationship to Prometheus due to shared use of the Thanos codebase and timing of activity, but that link remains unconfirmed.

Haron is designed for enterprise-focused double extortion. In addition to encrypting files, it threatens publication of stolen data through a dedicated leak site if victims do not negotiate. The malware drops ransom notes in text and HTA formats, appends an extension derived from the victim organization name, and uses implementation patterns associated with Thanos-derived families. Reverse-engineering has shown SmartAssembly obfuscation and layered string protection involving encrypted and compressed embedded resources.

Its functionality includes broad file targeting across documents, archives, databases, images, virtual disk files, and backup-related data; enumeration of local drives; termination of processes and services associated with security products, backup software, databases, mail servers, and office applications; and actions intended to inhibit recovery, including deletion of shadow copies and destruction of backup artifacts. Haron also modifies system settings related to network discovery and file sharing and contains logic referencing network shares, indicating support for encrypting accessible network resources. These behaviors align with post-compromise ransomware deployment against larger organizations rather than opportunistic consumer targeting.

Haron has been associated with campaigns against organizations considered capable of paying high-value ransoms. It is part of the broader wave of Thanos-based ransomware variants that appeared after the builder and related code became available to other actors, enabling rebranding and rapid creation of new extortion operations.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Post Exploitation

Operational record

1
YARA rules
1
Leak sites
0 available

MITRE ATT&CK

Haron in ATT&CK

26 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.