Charon Ransomware Emerges With APT-Style Tactics
ID: ca7f4002-cec2-5c58-94f1-347c33877da2
STIX ID: report--ca7f4002-cec2-5c58-94f1-347c33877da2
Feed Name: Dark Reading
Date Published: 2025-08-12
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers observed a new ransomware family named Charon deployed in targeted attacks against public sector and aviation organizations in the Middle East. The campaign uses advanced APT-style techniques—DLL sideloading (Edge.exe loading a malicious msedge.dll/SWORDLDR), multi-stage encrypted payloads hidden in DumpStack.log, and process injection into svchost.exe—allowing evasion of EDR and rapid network compromise; researchers note overlaps with Earth Baxia tradecraft but cannot definitively attribute the activity and recommend multilayered defenses to harden against DLL sideloading, process injection, and tampering of endpoint security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
