{
	"id": "9ef98560-0018-4120-8561-7f49914ae1d4",
	"created_at": "2026-04-06T00:09:26.991791Z",
	"updated_at": "2026-04-10T03:21:28.834157Z",
	"deleted_at": null,
	"sha1_hash": "816051906c0206bc2a1abdb603dbfb1bf0275e2a",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 49127,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-02 11:39:05 UTC\nHome \u003e List all groups \u003e List all tools \u003e List all groups using tool HermeticRansom\n Tool: HermeticRansom\nNames\nHermeticRansom\nPartyTicket\nElections GoRansom\nSonicVote\nCategory Malware\nType Ransomware\nDescription\n(Kaspersky) On February 24, 2022, Avast Threat Research published a tweet announcing the\ndiscovery of new Golang ransomware, which they called HermeticRansom. This malware was\nfound around the same time the HermeticWiper was found, and based on publicly available\ninformation from security community it was used in recent cyberattacks in Ukraine. The new\nransomware was likely used as a smokescreen for the HermeticWiper attack due to its non-sophisticated style and poor implementation.\nInformation\nMalpedia Playbook\nLast change to this tool card: 27 December 2022\nDownload this tool card in JSON format\nAll groups using tool HermeticRansom\nChanged Name Country Observed\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=306fecbd-0510-4b7e-8f15-6aa4f5f69efd\nPage 1 of 2\n\nUnknown groups\r\n  _[ Interesting malware not linked to an actor yet ]_  \r\n1 group listed (0 APT, 0 other, 1 unknown)\r\nSource: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=306fecbd-0510-4b7e-8f15-6aa4f5f69efd\r\nhttps://apt.etda.or.th/cgi-bin/listgroups.cgi?u=306fecbd-0510-4b7e-8f15-6aa4f5f69efd\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=306fecbd-0510-4b7e-8f15-6aa4f5f69efd"
	],
	"report_names": [
		"listgroups.cgi?u=306fecbd-0510-4b7e-8f15-6aa4f5f69efd"
	],
	"threat_actors": [],
	"ts_created_at": 1775434166,
	"ts_updated_at": 1775791288,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/816051906c0206bc2a1abdb603dbfb1bf0275e2a.pdf",
		"text": "https://archive.orkl.eu/816051906c0206bc2a1abdb603dbfb1bf0275e2a.txt",
		"img": "https://archive.orkl.eu/816051906c0206bc2a1abdb603dbfb1bf0275e2a.jpg"
	}
}