Hermes Ransomware

#Hermes • 2017-10

🇹🇼 Taiwan

Hermes ransomware appeared in DPRK-relevant activity around the 2017 Far Eastern International Bank heist, where BAE Systems observed Hermes alongside known Lazarus tools and assessed it may have served as distraction or cover during SWIFT-connected theft operations. Later reporting on Hermes 2.1 found retained code fragments from earlier Hermes binaries, destructive backup and shadow-copy deletion, local and network encryption behavior, and delivery to South Korean users through a compromised Korean website and the Magnitude exploit kit using CVE-2018-4878, while some reports cautioned that specific intent or attribution for newer samples remained uncertain.

Related Actors

Lazarus

Novetta

Novetta coined the name "Lazarus Group" as part of Operation Blockbuster, an industry coalition it led with partners including Kaspersky Lab and Cisco Talos that publicly disclosed its findings on 24 February 2016. Kaspersky's contribution to that release traced the actor's activity back to 2009, noted a spike from 2011 and steady growth from 2013, and folded malware and campaigns previously tracked separately, including Operation Troy, DarkSeoul, Hangman (2014-2015) and Wild Positron/Duuzer (2015), into a single cluster alongside the malware publicly attributed to the Sony Pictures Entertainment (SPE) breach. Novetta's own reverse engineering identified a spreader built specifically with SPE network and account details to deliver a destructive wiper. Across the analyzed malware set the group fielded a large toolkit of remote-administration trojans built on a shared code base, worm-style network spreaders, peer-to-peer staging tools, and web-server backdoors, alongside spearphishing that included a Hangul Word Processor zero-day, password-protected ZIP droppers, self-deleting batch scripts, and sandbox-evasion checks. Targets spanned financial, media and manufacturing organizations with a recurring focus on South Korea, and operations blended cyberespionage with destructive, data-wiping attacks.

Operation Blockbuster
First seen: 2016-02 • Last seen: 2026-08

Related Reports

« Back