Charon

Malware type
ransomware
Last IoC activity
2026-06-08 09:47:12
Profile updated
2026-07-07 14:52:16

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:ae country_code:sa

Context

According to Secui, this ransomware was used in attacks observed against Middle Eastern government agencies and the aviation industry.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Charon_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Charon (report)
  • secui.com — 1755675576.Sjnjz (report)
  • bluecyber.hashnode.dev — Apt Earth Baxia Charon Ransomware An In Depth Analysis (report)

External references