Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 10, 2026
- Feed role
- C2 / Distribution
- Host form
- 20 IP / 15 hostnames
Hive was a ransomware family and ransomware-as-a-service operation active from 2021 until a major international law-enforcement disruption in January 2023.
Profile source: Mallory opens in a new tabHive
Hive was a ransomware family and ransomware-as-a-service operation active from 2021 until a major international law-enforcement disruption in January 2023. It became one of the most prolific enterprise-focused ransomware threats of its period and was associated with double-extortion activity in which operators encrypted victim systems and threatened to publish stolen data. Hive was repeatedly linked to attacks against healthcare and other critical sectors, and public reporting and government advisories highlighted it as a significant risk to hospitals and broader enterprise environments.
Hive is primarily known as a Windows ransomware family, but the operation also fielded Linux encryptors for server-side targeting, including ESXi environments, reflecting the broader shift by major ransomware groups toward virtualization and Linux-based infrastructure. Research comparing ESXi lockers found no obvious code similarity between Hive’s ESXi encryptor and Babuk-derived Linux lockers used by some other ransomware families, indicating Hive maintained a distinct implementation in that area.
Operational reporting tied Hive-associated activity to common hands-on-keyboard ransomware tradecraft rather than a unique initial access mechanism. Observed and reported intrusion patterns associated with Hive deployments included abuse of compromised remote access, credential theft, lateral movement with administrative tooling, data exfiltration, and defense evasion prior to encryption. Hive-related attacks have also been associated with resilient infrastructure techniques such as fast flux. Multiple reports describe affiliates or related operators switching among ransomware payloads over time, with Hive appearing in the toolsets of broader cybercriminal ecosystems alongside families such as Ryuk, Conti, BlackCat, and LockBit.
The Hive ecosystem has been linked in public reporting to Russian-speaking cybercrime actors, including allegations involving Mikhail Pavlovich Matveev in development or deployment activity. After the January 2023 takedown, subsequent reporting frequently discussed Hunters International as a likely successor or spin-off due to code similarities and claimed acquisition of Hive-related assets, although the exact continuity between the operations has been debated.
C2 tracking
Derp observations, rolling seven-day window
Samples
32ead15908ca61088701ec6ee4c692658585746bafb52cce23c047d035fc91a5 a183360883d6cb14e40bfc0761663f3d44e55fe4ef364d09917fa5f388401b1d c322fa3e02a79ecead674bc4a8e67b71d14632427f8dc9a380b0f588941bbf1a c854317fdfc61855002f0cca0cba147c979a56878b8b211c5d512218877d680c f6a89afd80bcfccc8ade155c0ef92a770de44610efdcac2b6a21650dc136dca5 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 c2214a8b8c88c91a009891f3f10bbb2d8aa18a15580bd12c82dfcf2477f0c846 c26e2475ef60ba969bb66c9b464b498efb1da0bf7360ff7545c1db3b707bdbed Reported operators
DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.
Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
MITRE ATT&CK
Reporting
The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.