Hermes is a ransomware family used in financially motivated intrusions and associated in public reporting with North Korean activity, including APT38/Bluenoroff operations. It is known for encrypting victim files with AES-256 and has appeared both in targeted enterprise ransomware incidents and as a secondary payload delivered by other malware. Hermes has also been referenced in broader ransomware tradecraft discussions as one of the families used in hands-on-keyboard attacks.
Hermes has been observed delivered after initial compromise by other malware, notably AZORult, which downloaded and executed Hermes 2.1 following credential and data theft. Document-based infection chains involving password-protected files and macro-enabled lures have been reported in campaigns that ultimately deployed Hermes, indicating use in multi-stage attacks that combine theft and extortion.
The malware is primarily associated with Windows environments. Reporting also notes command-and-control infrastructure linked to Hermes infections, consistent with operator-managed ransomware deployment rather than purely autonomous spread. Hermes is relevant both as a standalone ransomware family and as part of larger financially motivated intrusion sets tied to banking and cryptocurrency targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The profile shows: Attributed to: North Korea Motivations: Financial gain, Espionage Targets: Finance, Cryptocurrency, Defense Malware used: WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Five recovered Hermes call logs show the agent was used to find a way to elevate privileges, scan for kernel vulnerabilities, enumerate services...
Threat actors used it to perform system enumeration, escalate privileges, discover files and services, and conduct network reconnaissance.
Five recovered Hermes call logs show the agent was used to... search for SUID and SGID binaries...
Threat actors used it to perform system enumeration, escalate privileges, discover files and services, and conduct network reconnaissance.
Threat actors used it to perform system enumeration, escalate privileges, discover files and services, and conduct network reconnaissance.
Additional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance.
The Spamhaus Botnet C&C (BGPCC) is designed to protect networks and their users from botnet traffic. It can be used to block traffic from/to servers on the internet that are operated by cybercriminals and used to control infected computers (bots) or exfiltrate data.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source AI assistant/agent that was abused by an operator to autonomously run reconnaissance and post-compromise commands inside Thailand's Ministry of Finance environment after human approval checks were disabled via YOLO mode. The article explicitly states Hermes is not a hacking tool and that this was abuse of a documented feature rather than a flaw in Hermes itself.
Named as malware used by Lazarus Group in the example APT profile.
Tags:Android apk GitHub GooglePlayStore Hermes malware NFCrelay RadzaRat React Smishing
Ransomware family listed as associated with BlueNorOff operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.