Netskope Threat Labs

Heracles

ATP Sandbox Adv. Heuristics

This generic detection identifies components of the Heracles command and control framework, which penetration testers and cyberattackers can both use to operate compromised hosts.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Backdoor.Heracles
ByteCode-MSIL.Downloader.Heracles
ByteCode-MSIL.Dropper.Heracles
ByteCode-MSIL.Malware.Heracles
ByteCode-MSIL.Ransomware.Heracles
ByteCode-MSIL.Spyware.Heracles
ByteCode-MSIL.Trojan.Heracles
Win32.Downloader.Heracles
Win32.PUA.Heracles
Win32.Trojan.Heracles