{"id":40190,"date":"2021-03-26T14:01:48","date_gmt":"2021-03-26T14:01:48","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32141\/Hades-Ransomware-Operators-Are-Hunting-Big-Game-In-The-US.html"},"modified":"2021-03-26T14:01:48","modified_gmt":"2021-03-26T14:01:48","slug":"hades-ransomware-operators-are-hunting-big-game-in-the-us","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/","title":{"rendered":"Hades Ransomware Operators Are Hunting Big Game In The US"},"content":{"rendered":"<p>An unknown threat group is deploying a variant of Hades in targeted attacks against US big game.&nbsp;<\/p>\n<p>On Friday, Accenture&#8217;s Cyber Investigation &amp; Forensic Response (CIFR) and Cyber Threat Intelligence (ACTI) teams published <a href=\"https:\/\/www.accenture.com\/us-en\/blogs\/cyber-defense\/unknown-threat-group-using-hades-ransomware\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">an analysis<\/a> into the latest Hades campaign which has been operating since at least <a href=\"https:\/\/twitter.com\/demonslay335\/status\/1339324224029274118\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">December 2020<\/a> until this month.&nbsp;<\/p>\n<p>According to the cybersecurity researchers, at least three major companies have been successfully attacked with the ransomware strain including a transport &amp; logistics company, a consumer products retailer, and a global manufacturer.&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/trucking-giant-forward-air-hit-by-new-hades-ransomware-gang\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Forward Air<\/a> was reportedly a past victim. <\/p>\n<p>Accenture says that the threat actors are focused on hunting organizations that generate at least $1 billion in annual revenue.&nbsp; <\/p>\n<p>In the latest recorded attacks, the threat actors take a hands-on approach and use a mix of custom tools and fileless approaches.&nbsp; <\/p>\n<p>Hades appears to infiltrate systems through internet-facing systems, Remote Desktop Protocol (RDP), or Virtual Private Network (VPN) setups using legitimate credentials &#8212; which may be obtained through brute-force attacks or stolen data dumps.&nbsp; <\/p>\n<p>Once Hades lands on a victim&#8217;s machine, it creates a copy of itself and relaunches itself via the command line. The &#8216;spare&#8217; copy is then deleted and an executable is unpacked in memory. A scan is then performed in local directories and network shares to find content to encrypt but each Hades sample secured uses a different extension.&nbsp; <\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\"> <\/section>\n<p>A ransom note, &#8220;HOW-TO-DECRYPT-[extension].txt,&#8221; is then dropped on the machine.&nbsp; <\/p>\n<p>The ransomware notes obtained through Hades samples direct victims to install Tor and a unique address appears to be generated for each target. In total, six have been traced, which may indicate further infections.&nbsp; <\/p>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/hub\/i\/r\/2021\/03\/25\/81a9e036-684a-4dc2-aba2-abe393464bd2\/resize\/1200xauto\/5864f69dc5e5512d284111f5128e8c9b\/screenshot-2021-03-25-at-13-45-37.png\" class alt=\"screenshot-2021-03-25-at-13-45-37.png\" height=\"auto\" width=\"1200\"><\/span><figcaption><span class=\"caption\"><\/span><\/figcaption><\/figure>\n<p>Similarities between ransom notes used by the Hades group and REvil ransomware operators. <a href=\"https:\/\/www.crowdstrike.com\/blog\/hades-ransomware-successor-to-indrik-spiders-wastedlocker\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">CrowdStrike considers<\/a> Hades to be the successor to <a href=\"https:\/\/www.zdnet.com\/article\/new-wastedlocker-ransomware-demands-payments-of-millions-of-usd\/\" target=\"_blank\" rel=\"noopener noreferrer\">WastedLocker ransomware<\/a>, a variant that has been deployed by REvil against US targets in past campaigns.&nbsp;<\/p>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/\" class=\"lazy\" alt=\"screenshot-2021-03-25-at-11-18-23.png\" height=\"auto\" width=\"1200\" data-original=\"https:\/\/www.zdnet.com\/a\/hub\/i\/r\/2021\/03\/25\/80559b89-0dc0-41c3-bcf8-bdf6369ed373\/resize\/1200xauto\/83c8b96f12690bfa4b43275f05535a12\/screenshot-2021-03-25-at-11-18-23.png\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/hub\/i\/r\/2021\/03\/25\/80559b89-0dc0-41c3-bcf8-bdf6369ed373\/resize\/1200xauto\/83c8b96f12690bfa4b43275f05535a12\/screenshot-2021-03-25-at-11-18-23.png\" class alt=\"screenshot-2021-03-25-at-11-18-23.png\" height=\"auto\" width=\"1200\"><\/span><\/noscript><figcaption><span class=\"caption\"><\/span><\/figcaption><\/figure>\n<p>Cobalt Strike and Empire are used to manage command-and-control (C2) servers and to maintain persistence. Batch scripts, log clearance, disabling endpoint antivirus products, and modifying Group Policy Object (GPO) to disable audit logging are all implemented to circumvent existing defenses.&nbsp;<\/p>\n<p>Hades also includes code obfuscation to avoid signature-based detection.&nbsp;<\/p>\n<p>A variety of reconnaissance tools are also utilized to grab network, host, and domain information and to achieve lateral movement through networks.&nbsp; <\/p>\n<p>&#8220;In addition, the threat actors operated out of the root of C:\\ProgramData where several executables tied to the intrusion set were found,&#8221; Accenture noted. <\/p>\n<p>Prior to encryption, Hades operators steal and archive data before whisking it away to a C2 in what is known as a double-extortion tactic: pay up, or risk the leak of corporate data online.&nbsp; <\/p>\n<p>&#8220;We assess with moderate confidence that the group&#8217;s operations have just begun, and that Hades activity will likely continue to proliferate into the foreseeable future, impacting additional victims,&#8221; Accenture says.&nbsp; <\/p>\n<p>CIFR and ACTI have published Indicators of Compromise (IoC) for the threat group and Hades variant.&nbsp; <\/p>\n<h3> Previous and related coverage <\/h3>\n<hr>\n<p><strong>Have a tip?<\/strong> Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0<\/p>\n<hr>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32141\/Hades-Ransomware-Operators-Are-Hunting-Big-Game-In-The-US.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":40191,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[1489],"class_list":["post-40190","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinemalwarecybercrimefraudcryptography"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hades Ransomware Operators Are Hunting Big Game In The US 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hades Ransomware Operators Are Hunting Big Game In The US 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-26T14:01:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"421\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hades Ransomware Operators Are Hunting Big Game In The US\",\"datePublished\":\"2021-03-26T14:01:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/\"},\"wordCount\":533,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png\",\"keywords\":[\"headline,malware,cybercrime,fraud,cryptography\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/\",\"name\":\"Hades Ransomware Operators Are Hunting Big Game In The US 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png\",\"datePublished\":\"2021-03-26T14:01:48+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png\",\"width\":1200,\"height\":421},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hades-ransomware-operators-are-hunting-big-game-in-the-us\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,malware,cybercrime,fraud,cryptography\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinemalwarecybercrimefraudcryptography\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Hades Ransomware Operators Are Hunting Big Game In The US\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hades Ransomware Operators Are Hunting Big Game In The US 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/","og_locale":"en_US","og_type":"article","og_title":"Hades Ransomware Operators Are Hunting Big Game In The US 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-03-26T14:01:48+00:00","og_image":[{"width":1200,"height":421,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hades Ransomware Operators Are Hunting Big Game In The US","datePublished":"2021-03-26T14:01:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/"},"wordCount":533,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png","keywords":["headline,malware,cybercrime,fraud,cryptography"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/","url":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/","name":"Hades Ransomware Operators Are Hunting Big Game In The US 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png","datePublished":"2021-03-26T14:01:48+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/hades-ransomware-operators-are-hunting-big-game-in-the-us.png","width":1200,"height":421},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hades-ransomware-operators-are-hunting-big-game-in-the-us\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,malware,cybercrime,fraud,cryptography","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinemalwarecybercrimefraudcryptography\/"},{"@type":"ListItem","position":3,"name":"Hades Ransomware Operators Are Hunting Big Game In The US"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40190","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=40190"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40190\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/40191"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=40190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=40190"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=40190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}