Haron appeared in July 2021 as a ransomware-as-a-service operation heavily borrowing from the defunct Avaddon ransomware (copying ransom notes and leak site structure) and built on the Thanos ransomware builder, targeting enterprise organizations with a six-day negotiation window.
Objectives
Executive Summary
Haron is a medium-sophistication criminal ransomware-as-a-service (RaaS) threat actor that emerged in July 2021. Operating as a RaaS group, they leverage the Thanos ransomware builder and mimic the defunct Avaddon ransomware operation's structure. Haron targets enterprise organizations with a six-day negotiation window to pressure victims into prompt payment of ransoms. The group's primary focus is financial gain through encryption-based extortion andansom demands.
Goals & Targeting
Haron's strategic objectives are centered around financial gain through the deployment of ransomware against enterprise targets. Their targeting profile appears to prioritize organizations where ransom payment is more likely due to high operational disruption costs, such as sectors like healthcare, education, or finance. The group's choice to mimic Avaddon and leverage the Thanos builder indicates a focus on efficiency over innovation, aiming to maximize their criminal enterprise through proven methods. By selecting enterprise targets, Haron seeks to maximize the potential payout while ensuring sufficient resources are available for negotiation.
Enhanced Description
Haron, first observed in July 2021, operates as a Ransomware-as-a-Service (RaaS) provider, utilizing the Thanos ransomware builder to distribute their payloads. The threat group has copied certain aspects from the defunct Avaddon ransomware operation, including ransom notes and leak site structures, suggesting an attempt to leverage established methodologies in the ransomware landscape. Haron's primary targets are enterprise organizations across various sectors, though specific industries have not been conclusively identified. Their modus operandi involves encrypting victim data and imposing a strict six-day negotiation window to pressure prompt payment of ransoms, which aligns with typical RaaS operational models. The group's focus on financial gain through encryption-based extortion has led to significant disruptions in targeted organizations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Haron's campaigns typically involve a rapid encryption process targeting enterprise networks, followed by a six-day window during which victims are pressured to contact the attackers for decryption keys. The group appears to favor established ransomware practices by leveraging known infrastructure and tools from previous operations like Avaddon. While their operational output has not been extensively documented, Haron's campaigns have caused significant disruptions in sectors where downtime equates to financial loss.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on open-source intelligence and known patterns of RaaS operations. While there is confidence in the general profile and capabilities attributed to Haron, specific details such as exact campaign targets, attack vectors used beyond standard ransomware techniques, or evidence of advanced persistence are limited. Data gaps include unclear targeting specifics (sectors/countries) and a lack of confirmed operational instances outside emulation.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics