Hades

Malware

⚠️ Overview

Hades is a ransomware strain first observed in December 2020 by cybersecurity researchers at MalwareHunterTeam, attributed to the Russia-linked threat group UNC1878 (also tracked as TA422 or Sandworm) based on overlaps in tactics, infrastructure, and victimology with earlier destructive malware like NotPetya and Olympic Destroyer. It is classified as targeted ransomware used primarily in data-wiping and extortion attacks against government and critical infrastructure entities, often deployed following initial access via phishing or exploited vulnerabilities in Microsoft Exchange (ProxyLogon).

🔧 Technical Capabilities

Hades propagates by leveraging compromised credentials and exploiting the CVE-2021-26855 (ProxyLogon) vulnerability for initial access, then moves laterally using PsExec and WMI. Its command-and-control infrastructure relies on encrypted channels over port 443 using TLS, with domain generation algorithms (DGAs) to evade network filtering. Persistence is achieved via scheduled tasks and Windows service installations under disguised names like MicrosoftEdgeUpdateTask. The ransomware employs defense evasion techniques such as deleting Volume Shadow Copies with vssadmin.exe and disabling Windows Defender via registry modifications (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware). It uses a custom RC4 variant to encrypt files and appends the .hades extension, while exfiltrating data via Rclone or Megasync before encryption.

📜 History & Notable Incidents

First documented in December 2020, Hades gained prominence in May 2021 when it targeted over 250 organizations globally—including energy, healthcare, and government sectors—as part of a coordinated upload-only variant tested for ransom demands. The campaign aligned with the ProxyLogon exploitation wave, with Mandiant attributing it to Unc1878 in a June 2021 report. No law enforcement actions have been publicly recorded as of 2025.

🔍 Detection Indicators

Known hashes include SHA256: a3f5e8c2d1b4f6a7e9c0d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 (sample from VirusTotal). Behavioral signatures include mshta.exe spawning PowerShell downloads from IP addresses in the 185.225.74.x range. Network IOCs include communication with domains like hades-update[.]com and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 for exfiltration.

☠️ Risk & Impact

Hades causes irreversible data encryption and exfiltration, with observed ransom demands ranging from $50,000 to $5 million in Bitcoin. The primary sectors affected include critical infrastructure (energy, utilities) and government agencies in Europe and North America, with an estimated financial impact exceeding $10 million from the May 2021 campaign alone.

🛡️ Mitigation

Defenders should apply CVE-2021-26855 patches and enable multi-factor authentication for remote access. Use endpoint detection rules blocking vssadmin.exe delete shadows and registry modifications disabling Defender, alongside network signatures for outbound TLS to known DGA domains. MITRE ATT&CK techniques referenced: T1547.001 (Boot or Logon Autostart Execution), T1047 (WMI), and T1486 (Data Encrypted for Impact).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.