Threat Actor Unknown origin
STARDUST CHOLLIMA
Also known as: Sapphire Sleet
Open-source reporting has claimed that the Hermes ransomware was developed by the North Korean group STARDUST CHOLLIMA (activities of which have been public reported as part of the “Lazarus Group”), because Hermes was executed on a host during the SWIFT compromise of FEIB in October 2017.
Indicators of Compromise 4
MITRE ATT&CK TTPs 7
T1027 T1029 T1059 T1071.001 T1105 T1195.002 T1610
Obfuscated Files or Information
Defense Evasion
Scheduled Transfer
Exfiltration
Command and Scripting Interpreter
Execution
Web Protocols
Command And Control
Ingress Tool Transfer
Command And Control
Compromise Software Supply Chain
Initial Access
Deploy Container
Defense Evasion