logo

Charon Ransomware Emerges With APT-Style Tactics

ID: ca7f4002-cec2-5c58-94f1-347c33877da2

STIX ID: report--ca7f4002-cec2-5c58-94f1-347c33877da2

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-08-12

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro researchers observed a new ransomware family named Charon deployed in targeted attacks against public sector and aviation organizations in the Middle East. The campaign uses advanced APT-style techniques—DLL sideloading (Edge.exe loading a malicious msedge.dll/SWORDLDR), multi-stage encrypted payloads hidden in DumpStack.log, and process injection into svchost.exe—allowing evasion of EDR and rapid network compromise; researchers note overlaps with Earth Baxia tradecraft but cannot definitively attribute the activity and recommend multilayered defenses to harden against DLL sideloading, process injection, and tampering of endpoint security.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.