Hermes is a Windows ransomware family first observed in 2017 and later distributed in multiple criminal and suspected state-linked operations. It encrypts victim data using per-file AES keys protected with RSA and appends a distinctive HERMES marker with encrypted key material to affected files rather than consistently renaming them. Hermes has been observed enumerating local drives and network resources, skipping some system-related directories, deleting shadow copies and backup-related data, and establishing persistence through Startup-folder execution. Some variants generate victim-specific RSA key material locally and store supporting artifacts on disk, while relying on Windows cryptographic APIs for key generation and encryption operations.
Hermes has been delivered through exploit-driven campaigns, including use of the Flash Player vulnerability CVE-2018-4878 via the GreenFlash Sundown exploit kit against South Korean users, and has also appeared in follow-on intrusion chains involving other malware. Reporting has linked Hermes to financially motivated and destructive operations, including use by Lazarus-linked clusters such as APT38 or BlueNoroff in bank-related activity, though attribution has not been uniformly conclusive across all Hermes incidents. Hermes is also notable for its code relationship to Ryuk: Ryuk is widely assessed to have reused or adapted Hermes code and retained several Hermes-specific implementation traits, including the file marker format.
Observed Hermes behavior includes persistence, encryption of local and network-accessible files, deletion of backups and shadow copies, and locale checks to avoid execution on systems configured for Russian, Belarusian, or Ukrainian languages. Victim targeting seen in public reporting includes enterprises, financial institutions, and South Korean users exposed through exploit-based delivery. Hermes has also been sold or circulated in criminal markets, enabling reuse by multiple operators and complicating attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GreenFlash Sundown had started to use this recent Flash zero-day to distribute the Hermes ransomware. The payload from this attack is Hermes ransomware, version 2.1.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GreenFlash Sundown had started to use this recent Flash zero-day to distribute the Hermes ransomware. The payload from this attack is Hermes ransomware, version 2.1.
Curiously, our research lead us to connect the nature of Ryuk’s campaign and some of its inner-workings to the HERMES ransomware, a malware commonly attributed to the notorious North Korean APT Lazarus Group.
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Some endpoints were unauthenticated, allowing the system to retrieve employee information, including names, departments, and SSO account identifiers.
This enabled the agents to map 21 connected government systems, including single sign-on infrastructure.
“The attacker used a website traffic-ranking service to find valuable targets in the list Strix produced and prioritized those running custom software.”
The framework used Hermes and OpenClaw, deploying up to 8 sub-agents in parallel to perform reconnaissance, credential attacks, API testing, data collection, and lateral movement. | Researchers found evidence that the agents discovered hidden API endpoints on a government web application that returned valid authenticated sessions without requiring credentials.
А иногда атакующий менял конфигурацию развертываний Kubernetes и создавал cron-задачи, которые восстанавливали веб-скиммер после удаления.
А иногда атакующий менял конфигурацию развертываний Kubernetes и создавал cron-задачи, которые восстанавливали веб-скиммер после удаления.
The cybersecurity firm also identified a Hermes agent skill designed to delete the stolen card data from the victim’s Magento database. Additionally, the agent deleted a bicycle retailer’s backup tables after being instructed to erase staging tables created within the database.
ИИ-агенты внедряли на сайты магазинов веб-скиммеры... добавлял вредоносный код в легитимные JavaScript-файлы и на страницы оплаты, встраивал его в блоки Google Tag.
The framework also conducted automated password spraying against an office automation portal. It used employee usernames collected from exposed APIs and solved CAPTCHA images with OCR. By testing predictable password patterns, the agents cracked 85 accounts across several rounds.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source AI assistant/agent that was abused by an operator to autonomously run reconnaissance and post-compromise commands inside Thailand's Ministry of Finance environment after human approval checks were disabled via YOLO mode. The article explicitly states Hermes is not a hacking tool and that this was abuse of a documented feature rather than a flaw in Hermes itself.
Hermes is referenced as the ransomware framework believed to have been adapted or converted into Ryuk.
Named as malware used by Lazarus Group in the example APT profile.
Mentioned only as a comparison point in attribution discussion regarding Ryuk.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.