Herm1t is the owner of VX Heavens website and virus coder from Ukraine. Most of his work focuses on Linux, FreeBSD and other types of Unix. He created Lacrimae virus which implements ''code integration'' (ZMist-like) technique and two variants of Futhork one of the few viruses in the LISP language.
In Spring of 2012, Herm1t was charged with computer crimes in Ukraine. His server was seized and the site was made unavailable. An online campaign known as "Saving Private Herm1t" was started on Facebook to raise funds for his legal defense. Security researchers urged Ukraine to drop the charges, saying the site was an extremely valuable resource to researchers and of little value to criminals. In July of 2013, VX Heaven returned to the Internet, apparently Herm1t was acquitted.
Viruses
Sources available here.
Home page: http://vx.netlux.org/herm1t/
Personal blog:
http://herm1t.vxer.org/
http://lj.rossia.org/users/herm1t/ (in russian)
Papers
- «Advanced EPO: Deeper, longer and harder» (Part 1), EOF#3
- «Caveat virus», Feb 2008 (Caveat)
- «From position-independent to self-relocatable viral code», Dec 2009 (RELx)
- «Hashin' the elves», Oct 2007 (Hasher)
- «Infecting ELF-files using function padding for Linux», Aug 2006 (Arches)
- «INT 0x80? No, thank you!», Nov 2007 (Pilot)
- «Reverse of a coin: A short note on segment alignment», Oct 2007 (Coin)
- «Tribute to PDP-11/UNIX, UNIX.Dawn virus», 2007 (Dawn)
Virus analysis
- P. Ferrie «Frankie say relax», VB, Aug 2011
- P. Ferrie «Making a hash of things», VB, Aug 2009 (Hasher)
- P. Ferrie «Can you spare a seg?», VB, Jul 2009 (Caveat)
- P. Ferrie «Heads or tails?», VB, Sep 2009 (Coin)
- P. Ferrie «Flying solo», VB, Sep, 2009 (Pilot)
- P. Ferrie «Crimea River», VB, Feb 2008 (Lacrimae)
- P. Ferrie «Life, the Universe, and Everything», MMPC, Sep 2008 (FortyTwo)
- K. Sapronov «2005: *nix Malware Evolution» (Grip)
- J. Kaminsky «Loathing Lupper in Linux» (Grip)
Interviews
- Perforin "Interview with herm1t", Dark Codez #3
- Alexey Vorobyev «The nature of the pathogen», Esquire (Russia) #33, May 2008
- izee «Interview with herm1t», EOF #2, Nov 2007
- Dan Grabaham «Warning: Virus!», .net #118, Dec 2003
Jeremy Kirk. CSO Online, Security experts push Ukraine to drop VX Heavens prosecution. 2012.04.11