Yet Another Distraction? A New Version of North Korean Ransomware Hermes Has Emerged
2018-02-08 • Intezer •
http://www.intezer.com/another-distraction-new-version-north-korean-ransomware-hermes/
Intezer analyzes a Hermes 2.1 ransomware sample after earlier reporting linked Hermes use to a Taiwan bank-heist distraction and described the ransomware as thought to have originated from Lazarus. Code-reuse analysis found that the newer Hermes sample was mostly changed but still retained key fragments and function-level matches with earlier Hermes binaries. The report also notes similarities to techniques known to be used by Lazarus, while cautioning that there was not enough information to determine the specific intent behind the new sample. The reappearance matters because the same ransomware code could be reused to distract from other operations such as intellectual-property theft, bank fraud, or additional intrusions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 851032eb03bc8ee05c381f7614a0cbf… | 2018-02-08 | 2020-03-09 |
| HASH | bcb96251c3e747c0deabadfecc4e0ca… | 2018-02-08 | 2018-02-08 |