Ladon

First seen
2021-06-15 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:08:13

Targeted industries: energy-and-utilities government-and-public-sector healthcare-and-pharmaceutical financial-services

Context

Ladon is a ransomware that encrypts files on the victim's system, demanding a ransom to restore access. It is known to target multiple industries and has been active in the wild since mid-2021.

Detection coverage

  • 4 YARA rules

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_LTM_Ladon (yara-rule)
  • DITEKSHEN_INDICATOR_TOOL_LTM_Ladonexp (yara-rule)
  • SEKOIA_Tool_Ladon_Strings (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_Ladon (yara-rule)

Reports & references

  • asec.ahnlab.com — 56236 (report)
  • asec.ahnlab.com — 47455 (report)
  • paloaltonetworks.com — Through The Cortex Xdr Lens Uncovering A New Activity Group Targeting Governments In The Middle East And Africa (report)
  • mandiant.widen.net — M Trends 2023 (report)
  • nattothoughts.substack.com — Reconnaissance Scanning Tools Used (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ladon (report)
  • github.com — Ladon (report)

External references