Hades is a Windows ransomware family first observed in December 2020 and linked to Evil Corp, also known as INDRIK SPIDER. It is a 64-bit derivative of WastedLocker with substantial code and functional overlap, additional obfuscation, and minor feature changes. Its emergence formed part of Evil Corp’s repeated ransomware rebranding following U.S. Treasury sanctions in 2019, intended to obscure attribution and circumvent restrictions affecting ransom payments.
Hades retains WastedLocker’s static configuration, multistage installation and persistence mechanisms, file and directory enumeration, and encryption functionality. The families share RSA routines used to protect AES encryption keys. Hades deletes volume shadow copies to impede recovery and includes self-deletion behavior. It leaves ransom notes directing victims to individualized Tor negotiation pages and uses Tox for operator communication. Hades campaigns have used MEGA cloud storage for data exfiltration alongside encryption-based extortion.
Hades is deployed in human-operated attacks against enterprise environments and has been delivered through SocGholish, a malware delivery framework associated with fake browser updates on compromised legitimate websites. It was linked to the December 2020 attack against freight and logistics company Forward Air, which disrupted operational and information technology systems. Subsequent Evil Corp ransomware variants, including Phoenix Locker and Macaw Locker, share close code relationships with Hades.
The ransomware is distinct from the same-named Go-based Windows and Linux backdoor identified in attacker staging infrastructure associated with a 2026 intrusion targeting Thailand’s Ministry of Finance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Some of the ransomware names used are WastedLocker, Hades, and Phoenix.
there were several reports that the threat actor behind Wasted Locker were no longer distributing this ransomware but had instead switched to another ransomware called Hades.
The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.
Once executed via any of the three delivery branches, the Hades-family payload aggressively harvests secrets from developer workstations and CI/CD environments.
"With Hades attacks, GOLD DRAKE made extensive use of Cobalt Strike..."
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
« T1059 — Command and Scripting Interpreter (Execution) »
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
GlassFish : scripts Node.js déployant des WAR shells ( shell.war , itcenter-docs.war )
Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
From July 9 to 13, Hunt.io's platform Attack Capture identified three simultaneous open directories hosted in Hong Kong, which contained exploit code for multiple CVEs, Web shells, suo5 HTTP tunnels, and custom scripts.
Persistance : Registry Run Key + tâche planifiée (Windows), cron job (Linux)
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications... and, on Windows, process hollowing and screenshot capture.
the attacker infrastructure had extensive post-exploitation tooling, such as the aforementioned Web shells as well as staged privilege-escalation exploit code targeting both Linux and Windows.
Hades ransomware is a 64-bit compiled variant of WastedLocker upgraded with supplementary code obfuscation and a few minor feature changes.
Active credential-stealing campaigns, such as Mini Shai-Hulud, Miasma, and Hades, embedding fake headers specifically engineered to fool AI-assisted review tools into marking code as benign.
Les binaires sont nommés d’après des processus légitimes : ctfmon , csrss , kworker , multipathd , accounts-daemon
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications... and, on Windows, process hollowing and screenshot capture.
From Hades onwards, we found a unique self-delete implementation including the waitfor command.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks...
The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise.
its core capabilities included interactive remote shell access, persistence tasks, in-memory execution, file transferring, and SOCKS proxying — a technique that turns a compromised machine into a relay point for network traffic.
The ransom notes contain a URL that directs the victims to a Tor site with info about the attack and a Tox messenger address they can use to contact Evil Corp's operators.
Forward Air suffered a ransomware attack by a new ransomware gang that has impacted the company's business operations. | On December 15, 2020, Forward Air Corporation ... detected a ransomware incident impacting its operational and information technology systems, which has caused service delays for many of its customers.
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware campaign that embeds deceptive fake headers to evade or manipulate AI-assisted code review.
Only referenced in a related-articles teaser, not part of the main incident.
A Shai-Hulud-related expansion into PyPI and npm that used .pth startup hooks, embedded prompt injection for AI-scanner evasion, and exfiltrated stolen data via attacker-created repositories.
A custom Windows and Linux implant written in Go that provides interactive remote shell access, persistence tasks, in-memory execution, file transfer, and SOCKS proxying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.