HermeticRansom, also known as PartyTicket, Elections GoRansom, and SonicVote, is Go-based ransomware targeting Windows systems. It was first observed on February 23, 2022, in attacks against Ukrainian organizations immediately before Russia’s full-scale invasion. It was deployed alongside HermeticWiper and appeared in campaigns that also used the HermeticWizard worm. Its role was predominantly that of decoy ransomware accompanying destructive operations rather than a conventional financially motivated extortion campaign.
HermeticRansom enumerates local drives and network shares, selects files for encryption, and excludes Windows operating-system and application directories to preserve system operation. It targets documents, images, archives, executables, media, databases, and configuration files. Its encryption routine processes up to nine one-megabyte blocks per file using AES-GCM, leaving subsequent data unencrypted, and appends an RSA-2048-encrypted file key. It renames affected files, creates a desktop ransom note directing victims to contact the operators, and launches numerous child processes to perform encryption. The malware lacks obfuscation and contains politically themed strings referencing Joe Biden and U.S. politics.
Errors in its encryption-key generation make encrypted files recoverable without paying a ransom. CrowdStrike published a decryption script, and Avast released a free graphical decryptor in March 2022.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HermeticRansom: Ransomware written in Go that encrypts files and displays a ransom message to the victim.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The function at __C__projects_403forBiden_wHiteHousE_init checks if the OS supports AVX ... and is also responsible for ... getting the time zone data.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based ransomware described in background summaries of attacks against Ukrainian organizations. It enumerates drives, renames selected files, encrypts their contents using AES, and writes a read_me.html ransom note. Deployment through Group Policy is reported in at least one instance.
Unsophisticated Golang ransomware observed in Ukraine around the HermeticWiper incidents; assessed as likely a smokescreen to distract from the wiper operation.
Malware used against organizations in Ukraine and grouped here with destructive wipers; despite its name, the content treats it within the set of wiper activity and provides a sample hash IOC.
A decoy ransomware used alongside HermeticWiper in attacks against Ukrainian organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.