hermes
- First seen
- 2017-02-01 00:00:00
- Malware type
- ransomware, wiper
- Family
- Malware family
- Last IoC activity
- 2026-07-06 22:55:07
- Profile updated
- 2026-07-07 13:04:23
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:tw
Context
Hermes is a ransomware family first observed in the wild in February 2017, believed to have been developed by a group operating out of Asia. It originally appeared as a Ransomware-as-a-Service (RaaS) offering on underground forums but later saw deployment in targeted attacks. Hermes uses AES-256 encryption to lock victim files and appends a variety of extensions (including .hrm and campaign-specific variants). The ransom note, often named DECRYPT_INFORMATION.html or DECRYPT_INFORMATION.txt, provides payment instructions via email. The ransomware gained notoriety in 2018 when it was used as a destructive wiper in the Far Eastern International Bank (FEIB) heist in Taiwan, where attackers deployed Hermes to cover their tracks after a SWIFT fraud operation. Over time, Hermes code has been re-used and integrated into other ransomware families, including some Ryuk builds, suggesting code sharing or purchase from the original developer. Distribution vectors have included phishing campaigns, malicious attachments, and exploitation of RDP services.
Detection coverage
- 3 YARA rules
Detection rules
- CAPE_Hermes (yara-rule)
- MALPEDIA_Win_Hermes_Auto (yara-rule)
- MALPEDIA_Win_Hermes_Ransom_Auto (yara-rule)
Reports & references
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- krebsonsecurity.com — Ransomware Gangs And The Name Game Distraction (report)
- ransomlook.io — Hermes (report)
- Trend Micro — Hermes Ransomware (report)
- Broadcom/Symantec — Hermes Ransomware (report)
- bleepingcomputer.com — Hermes Ransomware Used As A Wiper In Taiwan Bank Heist (report)
- blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
- i.blackhat.com — Eu 20 Rivera From Zero To Sixty The Story Of North Koreas Rapid Ascent To Becoming A Global Cyber Superpower (report)
- proofpoint.com — New Version Azorult Stealer Improves Loading Features Spreads Alongside (report)
- baesystemsai.blogspot.de — Taiwan Heist Lazarus Tools (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Hermes (report)
- vxhive.blogspot.com — Deep Dive Into Hermes Ransomware (report)
- web.archive.org — Enterprise Malware As A Service (report)
- malwarebytes.com — Hermes Ransomware Distributed To South Koreans Via Recent Flash Zero Day (report)
- blog.naver.com — 223416580495 (report)
- medium.com — Reversing Ryuk Eef8Ffd55F12 (report)
- youtube.com — Watch (report)