The Hades ransomware gang
Threat Actor
The Hades ransomware gang began operating in 2020. When encrypting a victim, it will create a ransom note named 'HOW-TO-DECRYPT-[extension].txt' that resembles notes used by the REvil ransomware group.
Incidents Associated with this Threat
- December 15, 2020: Ransomware Attack at Forward Air
Malware Used by this Threat Actor
No malware identified for this threat actor.
