Hades is a name used for multiple distinct malware families, most notably an Evil Corp-linked ransomware lineage and a separate previously undocumented cross-platform Go implant used in a 2026 espionage intrusion targeting Thailand’s Ministry of Finance. Because the same name has been applied to unrelated malware, attribution and classification require context.
As ransomware, Hades emerged in late 2020 and has been linked by multiple researchers to Evil Corp, also known as INDRIK SPIDER and the Dridex gang. In that usage, Hades is assessed as a 64-bit variant or rebrand closely related to WastedLocker, with substantial code and functional overlap. It preserves core ransomware behaviors such as file and directory enumeration and encryption, while incorporating additional obfuscation and minor feature changes. The Hades ransomware branding is widely assessed as part of Evil Corp’s repeated renaming strategy to evade sanctions-related scrutiny and preserve monetization after OFAC action against the group. Reporting also indicates Hades operations may include data theft to increase pressure on victims, and the family has been associated with enterprise-targeted, human-operated intrusions. Delivery has been observed via the SocGholish malware distribution framework, including fake browser-update lures delivered through compromised websites.
Separately, Hades is also the operator-given name of a custom Windows and Linux implant written in Go that was recovered from attacker staging infrastructure during an active cyber-espionage operation against Thailand’s Ministry of Finance in 2026. In that usage, Hades functions as a backdoor designed to maintain persistent access after initial compromise. Windows and Linux builds share the same codebase and support encrypted command-and-control, persistence, interactive shell access, file transfer, and SOCKS proxying. Reported Windows-specific capabilities include process hollowing and screenshot capture. The implant was staged alongside webshells, HTTP tunneling tools, credential-access tooling, and local privilege-escalation exploits, indicating intended use for persistence and post-compromise expansion rather than initial access. The operation in which this implant appeared also involved extensive reconnaissance and credential abuse, and researchers assessed with low-to-medium confidence that the operators were Chinese-speaking or closely familiar with Chinese.
Because the supplied facts conflate these unrelated families under one name, Hades should be treated as an ambiguous malware label rather than a single coherent family unless the surrounding intrusion context clearly indicates either the Evil Corp ransomware lineage or the Go-based espionage backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hades ransomware has been linked to the Evil Corp cybercrime gang who uses it to evade sanctions imposed by the Treasury Department's Office of Foreign Assets Control (OFAC).
there were several reports that the threat actor behind Wasted Locker were no longer distributing this ransomware but had instead switched to another ransomware called Hades.
The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.
Once executed via any of the three delivery branches, the Hades-family payload aggressively harvests secrets from developer workstations and CI/CD environments.
"With Hades attacks, GOLD DRAKE made extensive use of Cobalt Strike..."
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
GlassFish : scripts Node.js déployant des WAR shells ( shell.war , itcenter-docs.war )
Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications... and, on Windows, process hollowing and screenshot capture.
Exécution en mémoire : Reflective PE loading via process hollowing dans svchost.exe (Windows)
Hades ransomware is a 64-bit compiled variant of WastedLocker upgraded with supplementary code obfuscation and a few minor feature changes.
Les binaires sont nommés d’après des processus légitimes : ctfmon , csrss , kworker , multipathd , accounts-daemon
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications... and, on Windows, process hollowing and screenshot capture.
Exécution en mémoire : Reflective PE loading via process hollowing dans svchost.exe (Windows)
From Hades onwards, we found a unique self-delete implementation including the waitfor command.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks...
Communication C2 : HTTPS avec URI imitant des assets statiques ( /assets/app.min.js , /assets/vendor.js , /assets/main.js )
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
its core capabilities included interactive remote shell access, persistence tasks, in-memory execution, file transferring, and SOCKS proxying — a technique that turns a compromised machine into a relay point for network traffic.
The ransom notes contain a URL that directs the victims to a Tor site with info about the attack and a Tox messenger address they can use to contact Evil Corp's operators.
Forward Air suffered a ransomware attack by a new ransomware gang that has impacted the company's business operations. | On December 15, 2020, Forward Air Corporation ... detected a ransomware incident impacting its operational and information technology systems, which has caused service delays for many of its customers.
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Shai-Hulud-related expansion into PyPI and npm that used .pth startup hooks, embedded prompt injection for AI-scanner evasion, and exfiltrated stolen data via attacker-created repositories.
A custom Windows and Linux implant written in Go that provides interactive remote shell access, persistence tasks, in-memory execution, file transfer, and SOCKS proxying.
Previously unknown malware implant with 62 builds found on the attacker-controlled server for Windows and Linux; no confirmation it was deployed inside the Thai Ministry of Finance network.
A previously unreported Go-based implant used in a suspected cyberespionage campaign against Thailand's Ministry of Finance to provide persistent access and support post-compromise activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.