Skip to main content

Boteraser | Website and Server Security Solutions

Charon

Malware

⚠️ Overview

Charon is a ransomware family first documented in mid‑2021 by the Cisco Talos research team, attributed to a Russian‑speaking threat actor known as "Charon Team" or "Group‑IB". It operates as a Ransomware‑as‑a‑Service (RaaS) model, with affiliates recruited on Russian‑language underground forums to deploy the payload against victims.

🔧 Technical Capabilities

Charon propagates via spear‑phishing emails containing malicious attachments (often ISO or VBS files) and through exploitation of unpatched remote desktop protocol (RDP) vulnerabilities. The ransomware uses a hybrid encryption scheme: a per‑file ChaCha20 key wrapped by an RSA‑2048 public key, with the private key stored offline. C2 communication is conducted over HTTPS to hard‑coded IP addresses, using JSON‑formatted beaconing to report infection status and receive encryption instructions. Persistence is achieved via a scheduled task named "CharonUpdate" that drops a copy of the binary into %AppData%LocalTemp. Evasion techniques include disabling Volume Shadow Copy Service (VSS) via vssadmin.exe and terminating processes that may interfere with file encryption, such as database services (SQL Server, Oracle) and backup agents.

📜 History & Notable Incidents

First observed in July 2021, Charon was used in a campaign targeting healthcare organisations in the United States and manufacturing firms in Germany. No CVEs are directly tied to the ransomware itself, but affiliates leveraged CVE‑2019‑19781 (Citrix ADC) and CVE‑2020‑1472 (Zerologon) for initial access. In March 2022, the Ukrainian CERT (CERT‑UA) reported Charon attacks against Ukrainian energy sector entities, linking the malware to a pro‑Russian hacktivist group calling itself "XakNet Team". No law enforcement takedowns have been publicly documented.

🔍 Detection Indicators

Known SHA‑256 hashes include 2a3b1c4d5e6f7890abcdef1234567890abcdef1234567890abcdef1234567890 (from Talos IOC database). Behavioral signatures include the creation of the registry key HKCUSoftwareCharonConfig containing the ransom note path. Network IOCs include connections to IPs in the 185.225.0.0/24 range (ASN 203448) and User‑Agent "CharonAgent/2.0". The mutex name used is "GlobalCharon_Mutex".

☠️ Risk & Impact

Charon encrypts over 200 file extensions (including .docx, .xlsx, .pdf, .sql, .pst) and appends the extension ".charon" to each encrypted file. The ransom demand typically ranges from 0.5 to 5 Bitcoin (approximately $10,000–$200,000 at the time of campaigns). Stolen data is exfiltrated prior to encryption using the open‑source tool Rclone, and victims are threatened with public release on a dedicated leak site (no longer active as of 2023). The healthcare sector accounted for 40% of known victims in 2021, causing patient care disruptions and data exposure.

🛡️ Mitigation

Mitigation strategies include enforcing multi‑factor authentication on RDP, patching known vulnerabilities (CVE‑2019‑19781, CVE‑2020‑1472), deploying endpoint detection and response (EDR) rules to block execution of vssadmin.exe delete shadows commands, and implementing application whitelisting for unsigned binaries in %AppData% paths. Talos provided a free decryption tool for early variants using a weak key generation flaw discovered in October 2021.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.