Skip to content

Hive

Hive was an affiliate-based ransomware-as-a-service operation first observed in June 2021.

Profile source: Mallory opens in a new tab

Hive

Family profile

Hive was an affiliate-based ransomware-as-a-service operation first observed in June 2021. Affiliates targeted organizations across multiple sectors, including healthcare and software, using phishing attachments, exposed or vulnerable Remote Desktop Protocol services, and compromised VPN credentials for access. The operation employed double extortion: operators exfiltrated victim data, encrypted systems and files, and threatened public disclosure when payment was not made.

Hive encryptors were developed for Windows, Linux, FreeBSD, and VMware ESXi-oriented environments. Earlier versions were written in Go, while a major 2022 Windows variant was rewritten in Rust and used Curve25519 ECDH and XChaCha20-Poly1305 cryptographic operations. The malware supported selective local and network encryption, process and service termination, deletion of backup and shadow-copy data, disabling of recovery mechanisms, and attempts to impair endpoint security tooling. Hive affiliates also used reconnaissance, credential-access, remote-administration, and enterprise deployment tooling to expand attacks across victim networks.

U.S. law enforcement infiltrated Hive infrastructure beginning in 2022, provided decryption keys to victims, and publicly disrupted the operation in January 2023. Hive was associated with ransomware affiliate activity attributed in U.S. criminal proceedings to Mikhail Pavlovich Matveev, also known as Wazawaka and Boriselcin.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 20, 2026
Last activity
Sep 24, 2026
Feed role
C2 / Distribution
Host form
4 IP / 1 hostnames

Leading locations

  • CN1
  • GR1
  • NL1
  • RU1
  • US1

Leading providers

  • Contabo Inc.1
  • Hangzhou Alibaba Advertising Co.,Ltd.1
  • HOSTMEIN IKE1
  • Omegatech LTD1
  • PJSC Rostelecom1

Infrastructure traits

  • Hosting 4

Samples

Recent associated samples

Reported operators

Threat actors

5 named in public reporting
fin12

Hive ransomware is only about one year old, having been first observed in June 2021, but it has grown into one of the most prevalent ransomware payloads in the ransomware as a service (RaaS) ecosystem.

Wazawaka

Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.

WIZARD SPIDER

DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.

Conti

Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...

Storm-0501

...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.

Exploited software

Vulnerabilities linked to Hive

7 CVEs

MITRE ATT&CK

Hive in ATT&CK

58 distinct techniques

Techniques

58 techniques
T1040 Network Sniffing T1486 Data Encrypted for Impact T1497 Virtualization/Sandbox Evasion T1059 Command and Scripting Interpreter T1070 Indicator Removal T1490 Inhibit System Recovery T1129 Shared Modules T1562 Impair Defenses T1489 Service Stop T1027 Obfuscated Files or Information T1134 Access Token Manipulation T1059.003 Windows Command Shell T1569 System Services T1041 Exfiltration Over C2 Channel T1657 Financial Theft T1027.002 Software Packing T1007 System Service Discovery T1136 Create Account T1021.002 SMB/Windows Admin Shares T1480 Execution Guardrails T1135 Network Share Discovery T1021.001 Remote Desktop Protocol T1562.001 Disable or Modify Tools T1136.001 Local Account T1140 Deobfuscate/Decode Files or Information T1562.009 Safe Mode Boot T1197 BITS Jobs T1105 Ingress Tool Transfer T1080 Taint Shared Content T1547 Boot or Logon Autostart Execution T1485 Data Destruction T1021 Remote Services T1037 Boot or Logon Initialization Scripts T1112 Modify Registry T1560 Archive Collected Data T1560.001 Archive via Utility T1484.001 Group Policy Modification T1570 Lateral Tool Transfer T1027.009 Embedded Payloads T1484 Domain or Tenant Policy Modification T1037.003 Network Logon Script T1529 System Shutdown/Reboot T1049 System Network Connections Discovery T1090 Proxy T1564 Hide Artifacts T1070.004 File Deletion T1016 System Network Configuration Discovery T1218 System Binary Proxy Execution T1057 Process Discovery T1071 Application Layer Protocol T1190 Exploit Public-Facing Application T1219 Remote Access Tools T1082 System Information Discovery T1036 Masquerading T1091 Replication Through Removable Media T1068 Exploitation for Privilege Escalation T1568.001 Fast Flux DNS T1584 Compromise Infrastructure

Reporting

Research mentioning Hive

Aug 12
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RansomEXX

Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.

Jul 20
The Record Media

India says allegedly leaked nuclear plant files pose no safety risk | The Record from Recorded Future News

The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.

Jul 17
Cyberveille

Fuite de données : 19 000 fichiers de la centrale nucléaire de Kudankulam exposés par World Leaks | CyberVeille

Jul 17
Theravenfile

KUDANKULAM NUCLEAR POWER PLANT LEAK: AN ACCIDENTAL DISCLOSURE - THE RAVEN FILE

Jul 16
Cysecurity News

Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned - CySecurity News - Latest Information Security and Hacking Incidents

Jul 16
Teiss News

teiss - News - NPCIL denies sensitive data breach at Kudankulam nuclear plant, says leaked files involve only conventional systems

Jul 16
Teiss News

teiss - News - Ransomware group leaks data stolen from India’s largest nuclear plant

Jul 15
Malware News

Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach - Malware News - Malware Analysis, News and Indicators

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.