hades logo

hades

1 incidentes 0 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: GOLD WINTER, Phoenix Locker, Hades Locker, WildFire Locker ransomware
Ver en IntelTracker → APTTrail →
Hades is a financially motivated ransomware group that emerged in December 2020 and is closely associated with the Russian-based cybercrime syndicate Evil Corp, also known as Indrik Spider. The group began using Hades ransomware as a successor to WastedLocker, another Evil Corp-developed ransomware, primarily to evade international sanctions imposed by the U.S. Treasury Department in December 2019. Hades operates as a private, human-operated ransomware, contrasting with the Ransomware-as-a-Service (RaaS) model, which indicates a highly engaged and hands-on approach by its operators. This group distinguishes itself by meticulously selecting high-value targets, typically large organizations with annual revenues exceeding $1 billion, to maximize financial gain. Hades is also referred to by the alias "Phoenix Locker." Unique operational characteristics include the use of customized Tor victim sites and Tox instant messaging for direct communication, diverging from centralized leak sites, a
Malware asociado
NetSupport, Donut, Dridex, SocGholish, Mimikatz, SocGholish
Tecnicas MITRE
T1070.001, T1484.001, T1587, T1027, T1078.002, T1074

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (SOCRadar)

ArgentinaBrazilCanadaGermanyUnited KingdomIrelandIndiaLuxembourgMexicoUnited States

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankCredit UnionsRail TransportationSoftware PublishersTransportation Equipment ManufacturingEnterprises & HoldingAccommodation

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com