Hermes is a Windows ransomware family first observed in February 2017. It encrypts victim files using AES-256 and protects per-file encryption keys with RSA. Hermes has been sold on underground markets, and its codebase was subsequently adapted into Ryuk. Code similarities between the two families do not establish that they share operators or developers.
Hermes 2.1 enumerates local drives and network resources for encryption while excluding selected directories and optical drives. It generates a victim-specific RSA key pair using the Windows CryptoAPI and appends a distinctive marker and RSA-protected AES key material to encrypted files without renaming them. It creates ransom notes and deletes volume shadow copies and backup files to impede recovery. This version relocates and relaunches itself, deletes its original executable, and establishes persistence through a Startup-folder script. It repeatedly requests administrative approval for a script rather than bypassing UAC, but continues encrypting files if approval is denied. It exits on systems configured with Russian, Belarusian, or Ukrainian language settings. Its key-management design does not require transmitting decryption keys to a command-and-control server.
Hermes 2.1 was distributed to South Korean users through compromised websites and malvertising-style redirections leading to the GreenFlash Sundown exploit kit, which exploited the Adobe Flash Player vulnerability CVE-2018-4878. Azorult has also downloaded Hermes as a follow-on payload. APT38 and Lazarus-linked operators have used Hermes in financial-sector intrusions, including the October 2017 attack against Taiwan's Far Eastern International Bank, and have deployed encryption to conceal evidence after theft operations. These operational associations do not establish North Korean authorship of the ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GreenFlash Sundown had started to use this recent Flash zero-day to distribute the Hermes ransomware. The payload from this attack is Hermes ransomware, version 2.1.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT38 has used Hermes ransomware to encrypt files with AES256.
GreenFlash Sundown had started to use this recent Flash zero-day to distribute the Hermes ransomware. The payload from this attack is Hermes ransomware, version 2.1.
Curiously, our research lead us to connect the nature of Ryuk’s campaign and some of its inner-workings to the HERMES ransomware, a malware commonly attributed to the notorious North Korean APT Lazarus Group.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Some endpoints were unauthenticated, allowing the system to retrieve employee information, including names, departments, and SSO account identifiers.
This enabled the agents to map 21 connected government systems, including single sign-on infrastructure.
“The attacker used a website traffic-ranking service to find valuable targets in the list Strix produced and prioritized those running custom software.”
The framework used Hermes and OpenClaw, deploying up to 8 sub-agents in parallel to perform reconnaissance, credential attacks, API testing, data collection, and lateral movement. | Researchers found evidence that the agents discovered hidden API endpoints on a government web application that returned valid authenticated sessions without requiring credentials.
А иногда атакующий менял конфигурацию развертываний Kubernetes и создавал cron-задачи, которые восстанавливали веб-скиммер после удаления.
А иногда атакующий менял конфигурацию развертываний Kubernetes и создавал cron-задачи, которые восстанавливали веб-скиммер после удаления.
The cybersecurity firm also identified a Hermes agent skill designed to delete the stolen card data from the victim’s Magento database. Additionally, the agent deleted a bicycle retailer’s backup tables after being instructed to erase staging tables created within the database.
ИИ-агенты внедряли на сайты магазинов веб-скиммеры... добавлял вредоносный код в легитимные JavaScript-файлы и на страницы оплаты, встраивал его в блоки Google Tag.
The framework also conducted automated password spraying against an office automation portal. It used employee usernames collected from exposed APIs and solved CAPTCHA images with OCR. By testing predictable password patterns, the agents cracked 85 accounts across several rounds.
155.254.22.215 Staging and command server, AI console... 213.21.239.62 C2.
They then pasted 301 results into the console with a message that ended with 跑这些 用代理 只扫高危 (“run these, use the proxy, high severity only”).
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source AI assistant/agent that was abused by an operator to autonomously run reconnaissance and post-compromise commands inside Thailand's Ministry of Finance environment after human approval checks were disabled via YOLO mode. The article explicitly states Hermes is not a hacking tool and that this was abuse of a documented feature rather than a flaw in Hermes itself.
Hermes is referenced as the ransomware framework believed to have been adapted or converted into Ryuk.
Named as malware used by Lazarus Group in the example APT profile.
Mentioned only as a comparison point in attribution discussion regarding Ryuk.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.