Haron
Haron is a Windows ransomware family that emerged in 2021 and is widely assessed as a Thanos-derived strain written in C# on the .NET framework.
Profile source: Mallory opens in a new tabHaron
Family profile
Haron is a Windows ransomware family that emerged in 2021 and is widely assessed as a Thanos-derived strain written in C# on the .NET framework. It has also been noted for operational and presentation similarities to Avaddon, including closely matching ransom-note language, negotiation workflows, and leak-site structure, although attribution to Avaddon operators has not been established conclusively. Some reporting has also suggested a possible relationship to Prometheus due to shared use of the Thanos codebase and timing of activity, but that link remains unconfirmed.
Haron is designed for enterprise-focused double extortion. In addition to encrypting files, it threatens publication of stolen data through a dedicated leak site if victims do not negotiate. The malware drops ransom notes in text and HTA formats, appends an extension derived from the victim organization name, and uses implementation patterns associated with Thanos-derived families. Reverse-engineering has shown SmartAssembly obfuscation and layered string protection involving encrypted and compressed embedded resources.
Its functionality includes broad file targeting across documents, archives, databases, images, virtual disk files, and backup-related data; enumeration of local drives; termination of processes and services associated with security products, backup software, databases, mail servers, and office applications; and actions intended to inhibit recovery, including deletion of shadow copies and destruction of backup artifacts. Haron also modifies system settings related to network discovery and file sharing and contains logic referencing network shares, indicating support for encrypting accessible network resources. These behaviors align with post-compromise ransomware deployment against larger organizations rather than opportunistic consumer targeting.
Haron has been associated with campaigns against organizations considered capable of paying high-value ransoms. It is part of the broader wave of Thanos-based ransomware variants that appeared after the builder and related code became available to other actors, enabling rebranding and rapid creation of new extortion operations.
Capabilities
- Defense Evasion
- Exfiltration
- Post Exploitation
Operational record
MITRE ATT&CK