HermeticRansom is a Go-based ransomware family deployed in destructive campaigns targeting organizations in Ukraine around the start of Russia’s 2022 invasion. It is also tracked as PartyTicket by some vendors and has been widely assessed as a faux or decoy ransomware component used alongside HermeticWiper and, in some intrusions, the HermeticWizard propagation tool. Rather than fitting the model of a mature profit-driven ransomware operation, it appears to have been used primarily to add disruption, distract defenders, and obscure concurrent wiping activity.
The malware encrypts files on local drives and network shares while avoiding core operating-system directories in order to keep the host running long enough to complete its activity. It drops a ransom note and renames encrypted files with a distinctive added extension. Technical analysis showed that it uses per-file symmetric encryption combined with an embedded RSA public key, but its cryptographic implementation contains serious flaws. Multiple researchers concluded that the encryption routine is breakable and slow, and free decryptors were released as a result. These implementation weaknesses, together with the campaign context and political messaging embedded in the malware, reinforced assessments that extortion was likely not its primary purpose.
HermeticRansom has been associated with attacks against Ukrainian entities and with broader victimology that included organizations in sectors such as financial services, defense, aviation, and IT services in Ukraine, Lithuania, and Latvia. The activity has been discussed in the context of Russia-aligned destructive operations, and some reporting places the broader Hermetic malware cluster within Sandworm-linked campaigns, although direct attribution of HermeticRansom itself has not always been stated with certainty. Overall, HermeticRansom is best understood as a disruptive ransomware-like payload used in support of destructive intrusion objectives rather than as a conventional standalone ransomware business operation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The function at __C__projects_403forBiden_wHiteHousE_init checks if the OS supports AVX ... and is also responsible for ... getting the time zone data.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unsophisticated Golang ransomware observed in Ukraine around the HermeticWiper incidents; assessed as likely a smokescreen to distract from the wiper operation.
Malware used against organizations in Ukraine and grouped here with destructive wipers; despite its name, the content treats it within the set of wiper activity and provides a sample hash IOC.
A decoy ransomware used alongside HermeticWiper in attacks against Ukrainian organizations.
Decoy ransomware used alongside HermeticWiper operations (likely to mask destructive intent).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.