Skip to main content
JS
Jacob Santos

Jacob Santos

Threat Hunter, Researcher and Builder

Sr. Threat Researcher | Trend AI
17
Articles
14
Threads
10+
Tools
10+
Talks
New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises
Trend AI Research Blog Aug 2025

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises

RansomwareAPT CrossoverDLL Sideloading

Charon ransomware blurs the line between APT operations and cybercrime by adopting techniques previously attributed to Earth Baxia, a state-sponsored threat actor. The group leverages DLL sideloading through legitimate Microsoft Edge binaries, uses hybrid Curve25519/ChaCha20 encryption that makes file recovery virtually impossible, and employs multi-stage loaders to evade detection. This analysis maps the crossover between APT tradecraft and ransomware operations, including shared infrastructure indicators and tooling overlaps.