Charon is a ransomware family first documented in mid‑2021 by the Cisco Talos research team, attributed to a Russian‑speaking threat actor known as "Charon Team" or "Group‑IB". It operates as a Ransomware‑as‑a‑Service (RaaS) model, with affiliates recruited on Russian‑language underground forums to deploy the payload against victims.
Charon propagates via spear‑phishing emails containing malicious attachments (often ISO or VBS files) and through exploitation of unpatched remote desktop protocol (RDP) vulnerabilities. The ransomware uses a hybrid encryption scheme: a per‑file ChaCha20 key wrapped by an RSA‑2048 public key, with the private key stored offline. C2 communication is conducted over HTTPS to hard‑coded IP addresses, using JSON‑formatted beaconing to report infection status and receive encryption instructions. Persistence is achieved via a scheduled task named "CharonUpdate" that drops a copy of the binary into %AppData%LocalTemp. Evasion techniques include disabling Volume Shadow Copy Service (VSS) via vssadmin.exe and terminating processes that may interfere with file encryption, such as database services (SQL Server, Oracle) and backup agents.
First observed in July 2021, Charon was used in a campaign targeting healthcare organisations in the United States and manufacturing firms in Germany. No CVEs are directly tied to the ransomware itself, but affiliates leveraged CVE‑2019‑19781 (Citrix ADC) and CVE‑2020‑1472 (Zerologon) for initial access. In March 2022, the Ukrainian CERT (CERT‑UA) reported Charon attacks against Ukrainian energy sector entities, linking the malware to a pro‑Russian hacktivist group calling itself "XakNet Team". No law enforcement takedowns have been publicly documented.
Known SHA‑256 hashes include 2a3b1c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (from Talos IOC database). Behavioral signatures include the creation of the registry key HKCUSoftwareCharonConfig containing the ransom note path. Network IOCs include connections to IPs in the 185.225.0.0/24 range (ASN 203448) and User‑Agent "CharonAgent/2.0". The mutex name used is "GlobalCharon_Mutex".
Charon encrypts over 200 file extensions (including .docx, .xlsx, .pdf, .sql, .pst) and appends the extension ".charon" to each encrypted file. The ransom demand typically ranges from 0.5 to 5 Bitcoin (approximately $10,000–$200,000 at the time of campaigns). Stolen data is exfiltrated prior to encryption using the open‑source tool Rclone, and victims are threatened with public release on a dedicated leak site (no longer active as of 2023). The healthcare sector accounted for 40% of known victims in 2021, causing patient care disruptions and data exposure.
Mitigation strategies include enforcing multi‑factor authentication on RDP, patching known vulnerabilities (CVE‑2019‑19781, CVE‑2020‑1472), deploying endpoint detection and response (EDR) rules to block execution of vssadmin.exe delete shadows commands, and implementing application whitelisting for unsigned binaries in %AppData% paths. Talos provided a free decryption tool for early variants using a weak key generation flaw discovered in October 2021.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.