Hades
Hades is ransomware associated in public reporting with Evil Corp and Indrik Spider activity, including intrusions tracked as UNC2165.
Profile source: Ransomware.live opens in a new tabHades
Family profile
Hades is ransomware associated in public reporting with Evil Corp and Indrik Spider activity, including intrusions tracked as UNC2165. This profile excludes the unrelated software supply-chain malware that also uses the Hades name.
Operational record
Reporting
Research mentioning Hades
AI assistant used in cyberattack on Thailand's Ministry of Finance | brief | SC Media
Researchers reported an active espionage intrusion targeting Thailand’s Ministry of Finance, tied to exposed attacker infrastructure at 43.246.208[.]207 and additional linked hosts in Hong Kong and Malaysia. The operation used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate ministry systems, map internal services, and assess privilege-escalation paths, while a previously undocumented cross-platform Go implant dubbed Hades was staged to maintain persistence on both Windows and Linux systems. Investigators also linked a VShell C2 server and the domain redhatupdating432.dnsrd.com to the activity. Recovered artifacts showed targeting of ministry administrative panels, mail infrastructure, Apache Hadoop and HiveServer2 environments, Apache Ambari, GlassFish, Alfresco, and internal document systems. The exposed directories contained exploit code, web shells, stolen credentials, credential-testing scripts, and Linux and IIS exploitation or privilege-escalation modules, while Hades reportedly supported command and control, file transfer, proxying, and screen capture. Investigators said the evidence indicates compromised internal access, though no data exfiltration had been confirmed at publication time, and assessed with low-to-moderate confidence that the operator was a Chinese-speaking or Sinophone threat actor based on infrastructure history, Chinese-language indicators, and use of FOFA.
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Hermes AI agent used to automate attack on Thai Finance Ministry
Ministère des Finances thaïlandais ciblé par un agent IA autonome Hermes et l'implant Hades | CyberVeille
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Threat Intelligence Report: Qilin (Agenda) Ransomware | CCB Belgium
Qilin ransomware has emerged as one of the most active cybercrime threats, with NCC Group identifying it as the most prolific ransomware group for the fifth consecutive quarter as global ransomware incidents climbed to 2,229 in Q2 2026. The group, also tracked as Agenda or Qilin Locker, operates a double-extortion RaaS model and has concentrated on high-GDP Western countries while reportedly avoiding CIS member states. Manufacturing and other industrial sectors have been hit hardest, alongside business services, technology, healthcare, and finance, with North America remaining the most affected region and Belgium reporting at least 15 alleged Qilin compromises that disrupted operations and exposed sensitive corporate data.