Hades is a Russia-nexus advanced persistent threat designation associated with Sandworm and the Olympic Destroyer sabotage operation against the 2018 Winter Olympics in Pyeongchang, South Korea. Olympic Destroyer was a destructive, self-replicating and self-modifying network worm deployed against Olympic organizers, suppliers and partners following reconnaissance and infiltration of target networks. The operation used extensive attribution deception, including forged malware metadata intended to implicate Lazarus. Subsequent Hades activity included spear-phishing against Russian financial organizations and biochemical threat-prevention organizations in Europe and Ukraine. Its multistage delivery chains used malicious Word macros, obfuscated PowerShell, HTA files containing JScript, RC4-encrypted payloads and PowerShell Empire agents for fileless post-exploitation control. Defense-evasion techniques included disabling PowerShell logging, randomized macro identifiers and command obfuscation. Compromised legitimate web servers supported malware delivery and command-and-control. Hades also exploited the Exim vulnerability CVE-2019-10149 to obtain access to exposed systems. Hades is distinct from the same-named enterprise ransomware operation associated with Evil Corp and from the Hades-family package-ecosystem malware cluster. These shared names do not establish a common actor. Similarities with Sofacy have been investigated, but do not establish that the groups are aliases.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named campaign expanding Shai-Hulud-style operations into PyPI and npm, using Python startup hooks and prompt injection against AI-based scanners.
Named as one of several ransomware groups that used SocGholish infections as an entry point for follow-on attacks.
A payload associated with the reported worm activity, protected by anti-analysis prompt-injection style comments intended to disrupt AI-assisted malware scanning.
Threat cluster in the Shai-Hulud supply chain campaign associated with payloads that steal secrets from developer workstations and CI/CD environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.