New Threat Actors BlackMatter and Haron Rear Their Heads

The infosec community spotted two new names on the threat landscape, in the face of BlackMatter and Haron. Both groups exhibit traits that make them look very similar to two big ransomware threat actors who supposedly went dark only recently.

Whether BlackMatter and Haron are simply rebrands of the REvil and DarkSide ransomware gangs is not too clear at the moment, but researchers are pointing out some similarities between them.

Both new threat actors are claiming to focus their efforts on huge targets that are capable of paying millions of dollars in ransom money, and are trying to don the Robin Hood outfit, claiming to never attack educational organizations, healthcare and critical infrastructure institutions - something that DarkSide was famous for.

Curiously, as Threatpost reported, BlackMatter have also promised free decryption tools if one of the gang's affiliates steps on the wrong organization's toes and pulls off a stunt similar to the attack on Colonial Pipeline that crippled US East Coast fuel deliveries earlier this year, when a DarkSide affiliate using the group's ransomware-as-a-service model hacked Colonial Pipeline.

Haron's malware was analyzed by South Korean security researchers in July 2021 and they discovered a lot of curious similarities between the tool Haron use and the older Avaddon group ransomware.

Avaddon is also one of the threat actors who cut and ran after the massive upheaval of legal action that followed the Colonial Pipeline attack. The group released nearly 3,000 ransomware decryption keys before going silent.

The ransom notes of the Avaddon and Haron ransomware are also strikingly similar, with large chunks of text that are completely identical.

When it comes to BlackMatter, researchers claim they have grounds to think this is actually a reincarnation of the DarkSide ransomware group.

There is currently no universal consensus or hard evidence that the two new names are indeed the old familiar faces, only rebranded and renamed under a slim new coat of paint. Only time can tell whether those are really the same people, using the same or slightly modified tools and techniques or completely new threat actors. Sadly, neither prospect is particularly encouraging.

July 29, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.