New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises


Trend Micro researchers recently identified a new ransomware family called Charon, deployed in a targeted attack observed in the Middle East’s public sector and aviation industry.

The threat actor employed a DLL sideloading technique notably similar to tactics previously documented in the Earth Baxia campaigns, which have historically targeted government sectors. The attack chain leveraged a legitimate browser-related file, Edge.exe (originally named cookie_exporter.exe), to sideload a malicious msedge.dll (SWORDLDR), which subsequently deployed the Charon ransomware payload. Analysis of the msedge.dll component revealed it was designed to load a file named DumpStack.log, which was absent from the Trend Micro initial telemetry.

Read more…
Source:Trend Micro


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Internet Archive attackers email support users: “Your data is now in the hands of some random guy”

    October 21, 2024

    Those who hacked the Internet Archive haven’t gone away. Users of the Internet Archive who have submitted helpdesk tickets are reporting replies to the tickets from the hackers themselves. Internet Archive, most known for its Wayback Machine, is a digital library that allows users to look at website snapshots from the past. It is often used ...

  • London taxi drivers wrongly hit with Ulez charges after TfL cyber attack

    October 13, 2024

    Thousands of black cab drivers have been wrongly hit with Ulez and Congestion Charge fines after the cyber attack against London’s transport authority. The Licensed Taxi Drivers’ Association (LTDA) said it had received thousands of calls this week from panicking cabbies who had begun receiving automated penalties from Transport for London (TfL). Read more… Source: MSN News Sign up ...

  • RDDoS Attack: What to Do if Hackers Demand a Ransom

    October 10, 2024

    DDoS attacks have evolved from simple disruptions into serious threats, with cybercriminals using them to demand ransoms and fill their cryptocurrency wallets. These attackers often operate like modern-day mafiosi, issuing threats and demanding payments. Pay up, or face two outcomes: either the attacks will start, or they simply won’t stop. In this article, StormWall researchers will ...

  • Largest water utility company in the US says it was targeted by a cyberattack

    October 8, 2024

    American Water Works, the nation’s largest regulated water and wastewater utility company, announced Monday that it was hit by a cyberattack earlier this month, prompting it to pause billing for its millions of customers. The Camden, New Jersey-based utility company said it became aware of “unauthorized activity” in their computer networks and systems last Thursday, which ...

  • Ransomware Attackers Target Kansas Water Treatment Facility

    September 24, 2024

    On Sunday, a cyber attack on a water utility in Arkansas City, Kansas prompted its treatment facility to revert to manual operations. The city manager, Randy Frazer, confirmed that the water supply remains unaffected and safe, with no disruption to service reported. The plant’s manual operation is a precautionary measure to enhance security while the situation ...

  • UK: Cyber incident ‘was an accident – not an attack’

    September 23, 2024

    A cyber incident which forced a council to shut down its IT systems was not an “attack, it was an accident”, it is understood. Tewkesbury Borough Council declared a major incident on 4 September after the incident, which a source said was its “own systems testing its own security”. People selling or buying homes in the ...