Hermes is a Windows ransomware family first observed in 2017 and later distributed in multiple criminal and suspected state-linked operations. It encrypts victim data using per-file AES keys protected with RSA and appends a distinctive HERMES marker with encrypted key material to affected files rather than consistently renaming them. Hermes has been observed enumerating local drives and network resources, skipping some system-related directories, deleting shadow copies and backup-related data, and establishing persistence through Startup-folder execution. Some variants generate victim-specific RSA key material locally and store supporting artifacts on disk, while relying on Windows cryptographic APIs for key generation and encryption operations.
Hermes has been delivered through exploit-driven campaigns, including use of the Flash Player vulnerability CVE-2018-4878 via the GreenFlash Sundown exploit kit against South Korean users, and has also appeared in follow-on intrusion chains involving other malware. Reporting has linked Hermes to financially motivated and destructive operations, including use by Lazarus-linked clusters such as APT38 or BlueNoroff in bank-related activity, though attribution has not been uniformly conclusive across all Hermes incidents. Hermes is also notable for its code relationship to Ryuk: Ryuk is widely assessed to have reused or adapted Hermes code and retained several Hermes-specific implementation traits, including the file marker format.
Observed Hermes behavior includes persistence, encryption of local and network-accessible files, deletion of backups and shadow copies, and locale checks to avoid execution on systems configured for Russian, Belarusian, or Ukrainian languages. Victim targeting seen in public reporting includes enterprises, financial institutions, and South Korean users exposed through exploit-based delivery. Hermes has also been sold or circulated in criminal markets, enabling reuse by multiple operators and complicating attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GreenFlash Sundown had started to use this recent Flash zero-day to distribute the Hermes ransomware. The payload from this attack is Hermes ransomware, version 2.1.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GreenFlash Sundown had started to use this recent Flash zero-day to distribute the Hermes ransomware. The payload from this attack is Hermes ransomware, version 2.1.
Curiously, our research lead us to connect the nature of Ryuk’s campaign and some of its inner-workings to the HERMES ransomware, a malware commonly attributed to the notorious North Korean APT Lazarus Group.
Malware associated with BlueNorOff include: "DarkComet, Mimikatz, Nestegg, Macktruck, WannaCry, Whiteout, Quickcafe, Rawhide, Smoothride, TightVNC, Sorrybrute, Keylime, Snapshot, Mapmaker, net.exe, sysmon, Bootwreck, Cleantoad, Closeshave, Dyepack, Hermes, Twopence, Electricfish, Powerratankba, and Powerspritz"
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The framework “implements dedicated research phases it calls ‘Learning Cycles’ — autonomous sessions where the AI system searches vulnerability databases, GitHub repositories, and security research publications for techniques specifically applicable to its target government’s infrastructure,”
when one route hit a dead end, it spun up another agent to search the internet for fresh information and try a different approach
It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies - scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities. | First, the agents mapped the entire government ecosystem, extracting embedded URLs, API endpoints, OAuth client IDs, and Keycloak configuration objects from a single government portal.
the agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds. Eighty-four of the 85 cracked accounts successfully authenticated to the department's internal information system
Across 12 "attack waves," the "near-autonomous" system deployed up to eight sub-agents, each assigned its own targets and techniques, and broke into a Taiwanese government website. Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities
the agents also tested predictable password patterns based on each employee’s ID, and cracked 85 accounts across multiple password-spray rounds.
The researchers say the attackers assembled an autonomous hacking platform using open-source AI-agent frameworks, enabling multiple agents to simultaneously map networks, research vulnerabilities, attempt intrusions, and adapt tactics when an attack path failed.
Threat actors used it to perform system enumeration, escalate privileges, discover files and services, and conduct network reconnaissance.
The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed.
Ultimately, they compromised a government email system, the country's nuclear safety agency, IT supply chain vendors, and at least seven energy sector companies, finding and exploiting misconfigurations and vulnerabilities while stealing sensitive data, credentials, and other secrets as they moved across the network.
the illicit access allowed the agents to exfiltrate a ton of government information, including more than 2,564 personnel records, a full JSON export of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source AI assistant/agent that was abused by an operator to autonomously run reconnaissance and post-compromise commands inside Thailand's Ministry of Finance environment after human approval checks were disabled via YOLO mode. The article explicitly states Hermes is not a hacking tool and that this was abuse of a documented feature rather than a flaw in Hermes itself.
Hermes is referenced as the ransomware framework believed to have been adapted or converted into Ryuk.
Named as malware used by Lazarus Group in the example APT profile.
Mentioned only as a comparison point in attribution discussion regarding Ryuk.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.