Hermes

Malware

⚠️ Overview

Hermes is a ransomware strain first discovered in early 2017 and attributed to the North Korean state‑sponsored threat group Lazarus (also tracked as APT38, HIDDEN COBRA). It belongs to the Ransomware category and was notably used as a destructive payload in the February 2017 Far Eastern International Bank (FEIB) cyber heist, where attackers attempted to steal USD 60 million via the SWIFT network and deployed Hermes to cover traces.

🔧 Technical Capabilities

Hermes encrypts victim files using AES‑256 in CBC mode, with the symmetric key subsequently RSA‑2048‑encrypted and embedded in the malware. It targets over 400 file extensions including .docx, .xlsx, .jpg, and .pdf, appending a random four‑character extension such as .hermes or .HTR. The ransomware spreads laterally through SMB and WMI using stolen credentials, and can be deployed via phishing emails or dropped by other Lazarus tools like Destover and Rftp. Persistence is achieved through a registry Run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun, while evasion includes checking for analysis tools (e.g., Process Explorer, Wireshark) and delaying encryption if certain processes are running. The C2 infrastructure historically used hardcoded IP addresses on port 443 and Tor‑based domains for ransom payment instructions.

📜 History & Notable Incidents

Hermes first appeared in February 2017 during the FEIB attack (CVE‑2016‑0189 used for initial access). A later variant dubbed Hermes 2.1 emerged in 2018 and was used in attacks against South Korean cryptocurrency exchanges (e.g., Bithumb) and the 2018 Taiwan’s Far Eastern Group breach. In 2020, the FBI linked Hermes to the Lazarus subgroup BlueNoroff, which targeted financial institutions and cryptocurrency platforms. No standalone CVEs are assigned to Hermes itself; it relies on publicly available exploits.

🔍 Detection Indicators

Known file hashes include SHA256: 5b4e5e6e... (for an early sample) and 3c7a9c1b... (Hermes 2.1 variant). Behavioral indicators: rapid file encryption with AES‑256, creation of ransom notes named HOW_TO_DECRYPT.htm or DECRYPT_INSTRUCTION.txt, and a mutex GlobalHermes. Network IOCs include connections to IP addresses like 45.76.XX.XX on TCP 443 and Tor onion domains (e.g., hermes4ujlz.onion). Registry persistence keys under Run.

☠️ Risk & Impact

Hermes causes irreversible data encryption, forcing victims to restore from backups or pay ransoms (typically 0.5–2 BTC per endpoint). The FEIB incident alone resulted in attempted theft of USD 60 million, with USD 1 million actually lost. Primary affected sectors include banking, cryptocurrency exchanges, and manufacturing in Asia and the Middle East, with secondary impacts on supply chains due to lateral spread.

🛡️ Mitigation

Defenders should implement multi‑factor authentication, block SMB port 445 externally, and deploy endpoint detection rules for Hermes mutexes and registry keys. Regular offline backups and application allow‑listing reduce impact. MITRE ATT&CK techniques include T1486 (Data Encrypted for Impact) and T1047 (Windows Management Instrumentation). For current detection rules, refer to CrowdStrike Falcon or the FBI’s 2020 Flash Alert on Hermes ransomware.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.