Hades

Malware type
ransomware
Family
Malware family
Last IoC activity
2026-06-21 17:25:06
Profile updated
2026-07-07 12:59:58

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Context

Hades is a ransomware strain known for targeting various industries with file encryption attacks. It has been associated with several incidents where sensitive data was held for ransom.

Related threat objects

Reports & references

  • secureworks.com — Gold Winter (report)
  • services.google.com — Threat Horizons Report H1 2025 (report)
  • CrowdStrike — How Big Game Hunting Ttps Shifted After Darkside Pipeline Attack (report)
  • docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • advanced-intel.com — Adversarial Perspective Advintel Breach Avoidance Through Monitoring Initial Vulnerabilities (report)
  • huntandhackett.com — Advanced Ip Scanner The Preferred Scanner In The Apt Toolbox (report)
  • killingthebear.jorgetesta.tech — Evil Corp (report)
  • Mandiant — Unc2165 Shifts To Evade Sanctions (report)
  • assets.sentinelone.com — Sentinellabs Evilcorp (report)
  • sentinelone.com — S1 Sentinellabs Sanctionsbedamned Final 02 (report)
  • awakesecurity.com — Incident Response Hades Ransomware Gang Or Hafnium (report)
  • blog.truesec.com — Are The Notorious Cyber Criminals Evil Corp Actually Russian Spies (report)
  • twitter.com — 1381477874046169089 (report)
  • accenture.com — Unknown Threat Group Using Hades Ransomware (report)
  • accenture.com — Ransomware Hades (report)
  • bleepingcomputer.com — Evil Corp Switches To Hades Ransomware To Evade Sanctions (report)
  • secureworks.com — Hades Ransomware Operators Use Distinctive Tactics And Infrastructure (report)
  • ransomlook.io — Hades (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Hades (report)

External references