New Haron ransomware gang emerges, borrows from Avaddon and Thanos
Full article356 words · extracted from therecord.media · click to collapse
Malware analysts from South Korean security firm S2W Labs have discovered a new ransomware operation that launched in the cybercrime ecosystem this month that heavily borrows from past ransomware operations such as Thanos and the now-defunct Avaddon. Named Haron, the first samples linked to this gang have been spotted earlier this month. Just like the vast majority of ransomware operations today, the Haron gang goes after enterprise targets in order to maximize its profits and also runs a "leak site" where it threatens to publish data stolen from companies who refuse to pay for decrypting their files. But while Haron uses the same tactics used by more advanced ransomware families, S2W researchers say that under the hood, Haron is more of an amateurish Frankenstein, being built around code copied from other ransomware gangs. These similarities include: All of these suggest that the Haron gang had direct access to some parts of Avaddon's operation. However, it is unclear how this happened. It is unclear if the Haron gang purchased these items from the Avaddon gang directly or if they hired one of Avaddon's former members, most likely the person responsible for the gang's web-facing applications, such as Avaddon's payment and leak sites. But as S2W researchers point out, while the Haron gang had incorporated Avaddon's web-based systems into its operations, they did not have access to the Avaddon ransomware source code. Written in C++, the original Avaddon ransomware was an advanced ransomware strain, something superior to the C# codebase of the Thanos strain, also used by the Prometheus ransomware group.— The Brofessor (@Glacius_) July 19, 2021
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/new-haron-ransomware-gang-emerges-borrowing-from-avaddon-and-thanos