Hades
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-06-21 17:25:06
- Profile updated
- 2026-07-07 12:59:58
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Context
Hades is a ransomware strain known for targeting various industries with file encryption attacks. It has been associated with several incidents where sensitive data was held for ransom.
Related threat objects
- WildFire Locker (malware)
Reports & references
- secureworks.com — Gold Winter (report)
- services.google.com — Threat Horizons Report H1 2025 (report)
- CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- advanced-intel.com — Adversarial Perspective Advintel Breach Avoidance Through Monitoring Initial Vulnerabilities (report)
- huntandhackett.com — Advanced Ip Scanner The Preferred Scanner In The Apt Toolbox (report)
- killingthebear.jorgetesta.tech — Evil Corp (report)
- Mandiant — Unc2165 Shifts To Evade Sanctions (report)
- assets.sentinelone.com — Sentinellabs Evilcorp (report)
- sentinelone.com — S1 Sentinellabs Sanctionsbedamned Final 02 (report)
- awakesecurity.com — Incident Response Hades Ransomware Gang Or Hafnium (report)
- blog.truesec.com — Are The Notorious Cyber Criminals Evil Corp Actually Russian Spies (report)
- twitter.com — 1381477874046169089 (report)
- accenture.com — Unknown Threat Group Using Hades Ransomware (report)
- accenture.com — Ransomware Hades (report)
- bleepingcomputer.com — Evil Corp Switches To Hades Ransomware To Evade Sanctions (report)
- secureworks.com — Hades Ransomware Operators Use Distinctive Tactics And Infrastructure (report)
- ransomlook.io — Hades (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Hades (report)