Netskope Threat Labs

Hermes

ATP Sandbox Adv. HeuristicsAV

Hermes is a ransomware family associated with North Korean actors, documented in the Lazarus malware constellation and in reports on the country's cyber program. Its code base was later reused or imitated by other ransomware brands, and researchers have noted the family's resemblance to later strains such as MarraCrypt.

First seen
May 2022
Last seen
October 2026
Alert Name
Dropped:Generic.Ransom.Hermes.DB4079ED
Gen:Variant.Ransom.Hermes.109
Gen:Variant.Ransom.Hermes.111
Gen:Variant.Ransom.Hermes.113
Gen:Variant.Ransom.Hermes.136
Gen:Variant.Ransom.Hermes.137
Gen:Variant.Ransom.Hermes.22
Generic.Ransom.Hermes.0ABDB074
Generic.Ransom.Hermes.A6FE2991
Generic.Ransom.Hermes.DB4079ED