Uptime Hamster: 11d 15h 10mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza haron

haron

2 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
Haron is a ransomware group that emerged in July 2021, distinguished by its practice of borrowing elements from other established ransomware operations. The group's primary motivation is financial gain, achieved through double extortion tactics. It notably utilizes a leaked builder for the Thanos ransomware, written in C#, and mimics the negotiation and leak site designs of the defunct Avaddon ransomware group. While often compared to Avaddon, analysts generally consider Haron a distinct entity that leveraged existing resources rather than a direct rebranding, evidenced by its use of a different ransomware codebase. The group was observed to have initially insecure authentication processes for its dark web infrastructure.

Actores similares

Red Charonapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownft4zr2jzlqoyob7yg4fcpwyt37hox3ajajqnfkdvbfrkjioyunmqnpad.onionharon
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: haron
Tecnicas MITRE
T1059.001, T1566.001, T1047, T1069.002, T1021.001
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

AustraliaCanadaUnited KingdomLebanonUnited States

Sectores objetivo (SOCRadar)

Software PublishersEnterprises & HoldingAir TransportationManufacturingConstructionPublic AdministrationEducational ServicesWholesale TradeEnergy & Utilities Insurance

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com