Hades ransomware is a 64-bit Windows ransomware variant in the Evil Corp/INDRIK SPIDER malware lineage. First observed in December 2020, it has substantial code and functional overlap with WastedLocker, including its encryption, file and directory enumeration, static configuration, and multi-stage installation and persistence mechanisms. Hades adds obfuscation and minor implementation changes intended to complicate detection and attribution. It has been assessed as part of Evil Corp’s repeated ransomware rebranding activity following U.S. OFAC sanctions against the group. Related ransomware variants in this cluster include WastedLocker, Phoenix Locker, PayloadBIN, and Macaw Locker. Hades was used in human-operated attacks against enterprise organizations, including the 2020 intrusion affecting Forward Air, and operations may use stolen-data exposure as additional payment pressure. SocGholish has been observed delivering Hades through drive-by fake browser-update lures. The name Hades has also been separately applied to an unrelated, previously undocumented cross-platform Go backdoor associated with an apparent espionage operation targeting Thailand’s Ministry of Finance; that implant should not be conflated with Hades ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hades ransomware has been linked to the Evil Corp cybercrime gang who uses it to evade sanctions imposed by the Treasury Department's Office of Foreign Assets Control (OFAC).
there were several reports that the threat actor behind Wasted Locker were no longer distributing this ransomware but had instead switched to another ransomware called Hades.
The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.
Once executed via any of the three delivery branches, the Hades-family payload aggressively harvests secrets from developer workstations and CI/CD environments.
"With Hades attacks, GOLD DRAKE made extensive use of Cobalt Strike..."
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
« T1059 — Command and Scripting Interpreter (Execution) »
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
GlassFish : scripts Node.js déployant des WAR shells ( shell.war , itcenter-docs.war )
Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
From July 9 to 13, Hunt.io's platform Attack Capture identified three simultaneous open directories hosted in Hong Kong, which contained exploit code for multiple CVEs, Web shells, suo5 HTTP tunnels, and custom scripts.
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications... and, on Windows, process hollowing and screenshot capture.
the attacker infrastructure had extensive post-exploitation tooling, such as the aforementioned Web shells as well as staged privilege-escalation exploit code targeting both Linux and Windows.
Hades ransomware is a 64-bit compiled variant of WastedLocker upgraded with supplementary code obfuscation and a few minor feature changes.
Active credential-stealing campaigns, such as Mini Shai-Hulud, Miasma, and Hades, embedding fake headers specifically engineered to fool AI-assisted review tools into marking code as benign.
Les binaires sont nommés d’après des processus légitimes : ctfmon , csrss , kworker , multipathd , accounts-daemon
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications... and, on Windows, process hollowing and screenshot capture.
From Hades onwards, we found a unique self-delete implementation including the waitfor command.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks...
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
its core capabilities included interactive remote shell access, persistence tasks, in-memory execution, file transferring, and SOCKS proxying — a technique that turns a compromised machine into a relay point for network traffic.
The ransom notes contain a URL that directs the victims to a Tor site with info about the attack and a Tox messenger address they can use to contact Evil Corp's operators.
Forward Air suffered a ransomware attack by a new ransomware gang that has impacted the company's business operations. | On December 15, 2020, Forward Air Corporation ... detected a ransomware incident impacting its operational and information technology systems, which has caused service delays for many of its customers.
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware campaign that embeds deceptive fake headers to evade or manipulate AI-assisted code review.
Only referenced in a related-articles teaser, not part of the main incident.
A Shai-Hulud-related expansion into PyPI and npm that used .pth startup hooks, embedded prompt injection for AI-scanner evasion, and exfiltrated stolen data via attacker-created repositories.
A custom Windows and Linux implant written in Go that provides interactive remote shell access, persistence tasks, in-memory execution, file transfer, and SOCKS proxying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.