Haron is a Windows ransomware family that emerged in 2021 and is widely assessed as a Thanos-derived strain written in C# on the .NET framework. It has also been noted for operational and presentation similarities to Avaddon, including closely matching ransom-note language, negotiation workflows, and leak-site structure, although attribution to Avaddon operators has not been established conclusively. Some reporting has also suggested a possible relationship to Prometheus due to shared use of the Thanos codebase and timing of activity, but that link remains unconfirmed.
Haron is designed for enterprise-focused double extortion. In addition to encrypting files, it threatens publication of stolen data through a dedicated leak site if victims do not negotiate. The malware drops ransom notes in text and HTA formats, appends an extension derived from the victim organization name, and uses implementation patterns associated with Thanos-derived families. Reverse-engineering has shown SmartAssembly obfuscation and layered string protection involving encrypted and compressed embedded resources.
Its functionality includes broad file targeting across documents, archives, databases, images, virtual disk files, and backup-related data; enumeration of local drives; termination of processes and services associated with security products, backup software, databases, mail servers, and office applications; and actions intended to inhibit recovery, including deletion of shadow copies and destruction of backup artifacts. Haron also modifies system settings related to network discovery and file sharing and contains logic referencing network shares, indicating support for encrypting accessible network resources. These behaviors align with post-compromise ransomware deployment against larger organizations rather than opportunistic consumer targeting.
Haron has been associated with campaigns against organizations considered capable of paying high-value ransoms. It is part of the broader wave of Thanos-based ransomware variants that appeared after the builder and related code became available to other actors, enabling rebranding and rapid creation of new extortion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
wmic.exe ... Get-WmiObject Win32_Shadowcopy | ForEach-Object { $_Delete(); }
MITRE ATT&CK Technique ID Technique T1059 Command and Scripting Interpreter
The strings are stored in the onboard resource ... passed to the onboard SmartAssembly SimpleZip package ... AES decrypting the data ... base64 encoded data
fsutil file setZeroData offset=0 length=524288 “%s” & Del /f /q “%s” ... /s /f /q c:\*.VHD ... c:\*.bak ...
IPInfo: Error Parsing 'arp -a' results arp -a IPInfo: Error Retrieving 'arp -a' Results Client IP: http://icanhazip.com
tasklist /v /fo csv ... Task Manager SysListView32 Processes Procesos ... GetProcessId GetCurrentProcessId
Select * from Win32_ComputerSystem Manufacturer microsoft corporation Model VIRTUAL vmware VirtualBox ... PC Hardware ID:
Possible affected files: ... dat txt jpeg ... sql accdb ... vmx vmdk ...
Delete Shadows /all /quiet ... Get-WmiObject Win32_Shadowcopy | ForEach-Object { $_Delete(); }
when infected with Haron ransomware, “the extension of the encrypted file is changed to the victim’s name.”
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Thanos-derived ransomware variant that appends the targeted company name as an extension, drops RESTORE_FILES_INFO ransom notes, and operates a leak site for double extortion; the article suggests a possible operator link with Midas.
A ransomware variant listed among those most likely to re-extort victims in 2021.
A .NET-based ransomware sample analyzed through SmartAssembly string decoding. The content indicates Haron encrypts files, drops ransom notes, disables defenses and recovery options, kills processes/services, deletes shadow copies, and appears to support data theft/extortion.
Mentioned as a newly emerged ransomware group in the broader ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.