Hades is a name used in multiple distinct cyber threat contexts, but the strongest high-confidence usage in this corpus refers to a ransomware operation associated with Evil Corp. In that context, Hades conducted human-operated enterprise intrusions and has been linked to ransomware incidents affecting large organizations, including logistics victims in the United States. Reporting also places Hades among ransomware groups that have used SocGholish/FakeUpdates access and Advanced IP Scanner during intrusions, indicating reliance on established criminal access channels and hands-on-keyboard post-compromise reconnaissance. Observed behavior supports capabilities including initial access via third-party malware ecosystems, internal reconnaissance and scanning, data theft, and extortion-oriented ransomware operations. The name Hades also appears in some reporting as an alias or label associated with Russian state-linked activity, including references to Sandworm or Sofacy-related operations, but those usages are inconsistent across sources and are not sufficiently stable to merge confidently with the ransomware actor into a single attribution record. Separately, “Hades” is also used as a cluster name for a software supply-chain malware campaign targeting developer ecosystems, including npm and PyPI, where Hades-family payloads steal secrets from developer workstations and CI/CD environments. Because these usages likely refer to different actors or tracking constructs, they should be disambiguated carefully in operational use. For the ransomware actor, the dominant picture is a financially motivated cybercriminal operation tied in reporting to Evil Corp, using enterprise intrusion tradecraft, reconnaissance tooling, stolen-access ecosystems, ransomware deployment, and leak-oriented pressure tactics.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named campaign expanding Shai-Hulud-style operations into PyPI and npm, using Python startup hooks and prompt injection against AI-based scanners.
Named as one of several ransomware groups that used SocGholish infections as an entry point for follow-on attacks.
A payload associated with the reported worm activity, protected by anti-analysis prompt-injection style comments intended to disrupt AI-assisted malware scanning.
Threat cluster in the Shai-Hulud supply chain campaign associated with payloads that steal secrets from developer workstations and CI/CD environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.