Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety of data types using AES encryption. Hades Locker appends the names of encrypted files with the .~HL[5_random_characters] (first 5 characters of encryption password) extension. Known victims: 1 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

HadesLocker, an updated ransomware variant of WildFire Locker, targets systems for financial gain through encryption and extortion. It appends .~HL[5_random_characters] to files and demands ransoms for decryption keys. The threat actor operates with moderate sophistication, primarily targeting various sectors for organizational profit.

Goals & Targeting

The primary motivation is financial gain, targeting various sectors and countries indiscriminately due to the broad demand for ransoms across industries. Potential victims include healthcare, education, and businesses where downtime can be costly.

Enhanced Description

HadesLocker is a sophisticated ransomware variant known for its use of AES encryption to lock data. It replaces the original WildFire Locker by encrypting files and appending a specific extension to them. The ransomware's operations typically involve infiltrating systems through phishing campaigns or exploit kits, maximizing potential financial gain. First detected in 2020, HadesLocker has shown persistent activity with limited but impactful attacks.

Key Capabilities

  • Ransomware deployment via phishing or exploit kits
  • AES encryption of victim files
  • Threats of data deletion if demands are not met

MITRE ATT&CK Tactics

Intrusion execution
Credential access
Disruption

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom ransomware (HadesLocker)

Campaigns & Victims

Campaigns typically involve rapid encryption and immediate demands. Known for targeting single victims to date, but potential broader campaigns are possible. They may use dark web forums for shaming victims who refuse to pay.

IOC Patterns

  • Spear-phishing emails with malicious links
  • .~HL[5_random_characters] file extensions
  • File name changes during encryption

Recommended Actions

  • Patch systems regularly, monitor network traffic for unusual activities, train users on spotting phishing attempts

Suggested Tags

ransomware
financial-motivation
organizational-gain

Confidence Assessment

Low to medium confidence due to limited available data and known TTPs. Research gaps include exact infection vectors and specific tools used beyond the ransomware itself.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

13

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
financial-motivation
organizational-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 15, 2020
Last Seen
Dec 15, 2020
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.