Vendor Sheet
“Hermes” Unmasked: Tearing Down
“Hermes” illustrates a sophisticated, long-term cyber espionage campaign modeled in the MITRE ER7 Windows scenario. Conducted by Mustang Panda, it demonstrates how attackers operate stealthily through methods such as phishing, fileless execution, credential theft, lateral movement, and data exfiltration. Rather than a rapid attack, it progresses slowly, blending malicious actions with normal system activity to avoid detection. Starting from a single compromised user, attackers move across systems, targeting critical assets like domain controllers and file servers. This scenario highlights the need for advanced detection, visibility, and response to identify and stop threats that evade traditional security measures.
