Hades Defunct
Another Evil Corp rebrand. Targeted large revenue enterprises.0
Total Victims
2020-12-01
First Seen
N/A
Last Seen
23
Known TTPs
25.0d
Avg Delay
0
Negotiations
ONION URLS
ixltdyumdlthrtgx.onion
TOOLS
Certify
net.exe
FILE EXTENSIONS
.dead
ACTIVITY TIMELINE
TOP SECTORS
TOP COUNTRIES
ACTIVITY HEATMAP
| Date | Victim Name | Country | Sector | Status |
|---|---|---|---|---|
| No victims recorded | ||||
| Technique ID | Technique Name | Tactic |
|---|---|---|
| T1560.001 | Archive via Utility | Collection |
| T1090 | Proxy | Command and Control |
| T1105 | Ingress Tool Transfer | Command and Control |
| T1110.003 | Password Spraying | Credential Access |
| T1552.001 | Credentials In Files | Credential Access |
| T1055 | Process Injection | Defense Evasion |
| T1562.001 | Disable or Modify Tools | Defense Evasion |
| T1562.009 | Safe Mode Boot | Defense Evasion |
| T1016 | System Network Configuration Discovery | Discovery |
| T1018 | Remote System Discovery | Discovery |
| T1069 | Permission Groups Discovery | Discovery |
| T1059.005 | Visual Basic | Execution |
| T1204.002 | Malicious File | Execution |
| T1489 | Service Stop | Impact |
| T1490 | Inhibit System Recovery | Impact |
| T1491.001 | Internal Defacement | Impact |
| T1531 | Account Access Removal | Impact |
| T1133 | External Remote Services | Initial Access |
| T1195.002 | Compromise Software Supply Chain | Initial Access |
| T1136.001 | Local Account | Persistence |
| T1547.009 | Shortcut Modification | Persistence |
| T1068 | Exploitation for Privilege Escalation | Privilege Escalation |
| T1134 | Access Token Manipulation | Privilege Escalation |
No YARA rules
No IoCs
No ransom notes