Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Haron appeared in July 2021 as a ransomware-as-a-service operation heavily borrowing from the defunct Avaddon ransomware (copying ransom notes and leak site structure) and built on the Thanos ransomware builder, targeting enterprise organizations with a six-day negotiation window.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Haron is a medium-sophistication criminal ransomware-as-a-service (RaaS) threat actor that emerged in July 2021. Operating as a RaaS group, they leverage the Thanos ransomware builder and mimic the defunct Avaddon ransomware operation's structure. Haron targets enterprise organizations with a six-day negotiation window to pressure victims into prompt payment of ransoms. The group's primary focus is financial gain through encryption-based extortion andansom demands.

Goals & Targeting

Haron's strategic objectives are centered around financial gain through the deployment of ransomware against enterprise targets. Their targeting profile appears to prioritize organizations where ransom payment is more likely due to high operational disruption costs, such as sectors like healthcare, education, or finance. The group's choice to mimic Avaddon and leverage the Thanos builder indicates a focus on efficiency over innovation, aiming to maximize their criminal enterprise through proven methods. By selecting enterprise targets, Haron seeks to maximize the potential payout while ensuring sufficient resources are available for negotiation.

Enhanced Description

Haron, first observed in July 2021, operates as a Ransomware-as-a-Service (RaaS) provider, utilizing the Thanos ransomware builder to distribute their payloads. The threat group has copied certain aspects from the defunct Avaddon ransomware operation, including ransom notes and leak site structures, suggesting an attempt to leverage established methodologies in the ransomware landscape. Haron's primary targets are enterprise organizations across various sectors, though specific industries have not been conclusively identified. Their modus operandi involves encrypting victim data and imposing a strict six-day negotiation window to pressure prompt payment of ransoms, which aligns with typical RaaS operational models. The group's focus on financial gain through encryption-based extortion has led to significant disruptions in targeted organizations.

Key Capabilities

  • Ransomware creation and distribution
  • Use ofThanos ransomware builder features (e.g., kill switch, decryptor functionality)
  • Encryption of victim data with a specific extension
  • Negotiation framework to pressure quick payouts

MITRE ATT&CK Tactics

Credential Access
Execution Protection Evasion
Exfiltration
Impact
Defense-Evasion

ATT&CK Techniques

T1566.001 - Data Encrypted for Impact
T1249.001 - PowerShell for Scripting
T1485 - Credential Dumping
T1538.001 - Use of Account Access Removal Tools
T1071 - Email Collection

Software / Tooling

Thanos ransomware builder
Custom Ransomware
Encryptions scripts
Kill Switch Mechanisms
Decryptor Tools

Campaigns & Victims

Haron's campaigns typically involve a rapid encryption process targeting enterprise networks, followed by a six-day window during which victims are pressured to contact the attackers for decryption keys. The group appears to favor established ransomware practices by leveraging known infrastructure and tools from previous operations like Avaddon. While their operational output has not been extensively documented, Haron's campaigns have caused significant disruptions in sectors where downtime equates to financial loss.

IOC Patterns

  • Ransomware encryption of files with specific extensions
  • Use of Thanos builder features for kill switches and payload delivery
  • Spear-phishing emails with malicious links or attachments
  • C2 communication over HTTP/HTTPS channels
  • Lateral movement within networks using common tools

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts.
  • Deploy endpoint detection and response (EDR) solutions to monitor for encryption scripts and unusual processes.
  • Conduct regular data backups stored offline or in isolated environments as a recovery option.
  • Educate employees on recognizing suspicious emails and the risks of opening unknown links.
  • Enhance network segmentation to limit lateral movement potential.

Suggested Tags

Ransomware
Financial-Motivation
Enterprise-Targeting
Data-Theft

Confidence Assessment

The assessment is based on open-source intelligence and known patterns of RaaS operations. While there is confidence in the general profile and capabilities attributed to Haron, specific details such as exact campaign targets, attack vectors used beyond standard ransomware techniques, or evidence of advanced persistence are limited. Data gaps include unclear targeting specifics (sectors/countries) and a lack of confirmed operational instances outside emulation.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Motivation
Enterprise-Targeting
Data-Theft

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.