Charon
- Malware type
- ransomware
- Last IoC activity
- 2026-06-08 09:47:12
- Profile updated
- 2026-07-07 14:52:16
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:ae country_code:sa
Context
According to Secui, this ransomware was used in attacks observed against Middle Eastern government agencies and the aviation industry.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Charon_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Charon (report)
- secui.com — 1755675576.Sjnjz (report)
- bluecyber.hashnode.dev — Apt Earth Baxia Charon Ransomware An In Depth Analysis (report)