Inactive ransomware operator
← All groupshive
208 victims indexed · first seen 5 years ago · last activity 4 years ago
At a glance
- Status
- inactive
- First seen
- 5 years ago
- Last activity
- 4 years ago
- Primary sector
- Manufacturing · 16 hits
About
References
47 linksExternal sources curated by the MISP threat-intel community.
- malpedia.caad.fkie.fraunhofer.de/details/win.hive
- s3.amazonaws.com/talos-intelligence-site/production/document_files/files/000/095/787/original/ransomware-chats.pdf
- sentinelone.com/labs/hive-attacks-analysis-of-the-human-operated-ransomware-targeting-healthcare/
- trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-hive
- microsoft.com/en-us/security/blog/2022/07/05/hive-ransomware-gets-upgrades-in-rust/
- yoroi.company/wp-content/uploads/2022/07/Yoroi-On-The-Footsteps-of-Hive-Ransomware.pdf
- varonis.com/blog/hive-ransomware-analysis
- bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-hive-ransomware/
- inf.news/en/tech/c28d9382ab78a5ac3d8fc802f3f0f1e0.html
- healthcareitnews.com/news/fbi-issues-alert-about-hive-ransomware
- arxiv.org/pdf/2202.08477.pdf
- blog.group-ib.com/hive
- blogs.vmware.com/security/2022/09/esxi-targeting-ransomware-the-threats-that-are-after-your-virtual-machines-part-1.html
- github.com/rivitna/Malware/tree/main/Hive
- lifars.com/2022/02/how-to-decrypt-the-files-encrypted-by-the-hive-ransomware/
- media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/06/23093553/Common-TTPs-of-the-modern-ransomware_low-res.pdf
- query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE54L7v
- securityaffairs.co/wordpress/128232/security/recover-files-hive-ransomware.html
- thehackernews.com/2022/02/master-key-for-hive-ransomware.html
- therecord.media/academics-publish-method-for-recovering-data-encrypted-by-the-hive-ransomware/
Timeline
15 monthsTop countries
Top sectors
MITRE ATT&CK
85 techniques · 14 tacticsTactics
Techniques
- T1001.003Protocol or Service Impersonation
- T1003OS Credential Dumping
- T1003.001LSASS Memory
- T1003.003NTDS
- T1003.006DCSync
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1027Obfuscated Files or Information
- T1027.007Dynamic API Resolution
- T1027.012LNK Icon Smuggling
- T1027.016Junk Code Insertion
- T1036.005Match Legitimate Resource Name or Location
- T1036.007Double File Extension
- T1036.008Masquerade File Type
- T1041Exfiltration Over C2 Channel
- T1046Network Service Discovery
- T1047Windows Management Instrumentation
- T1048.003Exfiltration Over Unencrypted Non-C2 Protocol
- T1049System Network Connections Discovery
- T1052.001Exfiltration over USB
- T1053.005Scheduled Task
- T1057Process Discovery
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.003Windows Command Shell
- T1059.005Visual Basic
- T1059.007JavaScript
- T1069.002Domain Groups
- T1070Indicator Removal
- T1070.004File Deletion
- T1070.006Timestomp
- T1071.001Web Protocols
- T1072Software Deployment Tools
- T1074.001Local Data Staging
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1087.002Domain Account
- T1091Replication Through Removable Media
- T1095Non-Application Layer Protocol
- T1102Web Service
- T1105Ingress Tool Transfer
- T1106Native API
- T1119Automated Collection
- T1129Shared Modules
- T1140Deobfuscate/Decode Files or Information
- T1176.002IDE Extensions
- T1203Exploitation for Client Execution
- T1204.001Malicious Link
- T1204.002Malicious File
- T1205Traffic Signaling
- T1218.004InstallUtil
- T1218.005Mshta
- T1219.001IDE Tunneling
- T1219.002Remote Desktop Software
- T1505.003Web Shell
- T1518Software Discovery
- T1546.003Windows Management Instrumentation Event Subscription
- T1547.001Registry Run Keys / Startup Folder
- T1553.002Code Signing
- T1557Adversary-in-the-Middle
- T1560.001Archive via Utility
- T1560.003Archive via Custom Method
- T1564.001Hidden Files and Directories
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1567.002Exfiltration to Cloud Storage
- T1572Protocol Tunneling
- T1573.001Symmetric Cryptography
- T1574.001DLL
- T1574.005Executable Installer File Permissions Weakness
- T1583.001Domains
- T1583.006Web Services
- T1585.002Email Accounts
- T1586.002Email Accounts
- T1587.001Malware
- T1588.002Tool
- T1588.003Code Signing Certificates
- T1588.004Digital Certificates
- T1593Search Open Websites/Domains
- T1598.003Spearphishing Link
- T1608Stage Capabilities
- T1608.001Upload Malware
- T1622Debugger Evasion
- T1654Log Enumeration
- T1678Delay Execution
Recent victims
Loading…
Source
Updated 4 years agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
Get alerted the next time hive posts a victim.
Add hive to your watchlist — Pro pings you within 5 minutes of any new hive leak-site post, Telegram callout, or affiliate-rebrand inference.

