Skip to content

Hive

Hive was a ransomware family and ransomware-as-a-service operation active from 2021 until a major international law-enforcement disruption in January 2023.

Profile source: Mallory opens in a new tab

Hive

Family profile

Hive was a ransomware family and ransomware-as-a-service operation active from 2021 until a major international law-enforcement disruption in January 2023. It became one of the most prolific enterprise-focused ransomware threats of its period and was associated with double-extortion activity in which operators encrypted victim systems and threatened to publish stolen data. Hive was repeatedly linked to attacks against healthcare and other critical sectors, and public reporting and government advisories highlighted it as a significant risk to hospitals and broader enterprise environments.

Hive is primarily known as a Windows ransomware family, but the operation also fielded Linux encryptors for server-side targeting, including ESXi environments, reflecting the broader shift by major ransomware groups toward virtualization and Linux-based infrastructure. Research comparing ESXi lockers found no obvious code similarity between Hive’s ESXi encryptor and Babuk-derived Linux lockers used by some other ransomware families, indicating Hive maintained a distinct implementation in that area.

Operational reporting tied Hive-associated activity to common hands-on-keyboard ransomware tradecraft rather than a unique initial access mechanism. Observed and reported intrusion patterns associated with Hive deployments included abuse of compromised remote access, credential theft, lateral movement with administrative tooling, data exfiltration, and defense evasion prior to encryption. Hive-related attacks have also been associated with resilient infrastructure techniques such as fast flux. Multiple reports describe affiliates or related operators switching among ransomware payloads over time, with Hive appearing in the toolsets of broader cybercriminal ecosystems alongside families such as Ryuk, Conti, BlackCat, and LockBit.

The Hive ecosystem has been linked in public reporting to Russian-speaking cybercrime actors, including allegations involving Mikhail Pavlovich Matveev in development or deployment activity. After the January 2023 takedown, subsequent reporting frequently discussed Hunters International as a likely successor or spin-off due to code similarities and claimed acquisition of Hive-related assets, although the exact continuity between the operations has been debated.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 10, 2026
Feed role
C2 / Distribution
Host form
20 IP / 15 hostnames

Leading locations

  • CN10
  • US7
  • DE5
  • RU3
  • KR2
  • NL2
  • BR1
  • CA1
  • GR1
  • HK1
  • IE1
  • LU1

Leading providers

  • CHINA UNICOM China169 Backbone5
  • FEMO IT SOLUTIONS LIMITED3
  • Hangzhou Alibaba Advertising Co.,Ltd.2
  • Omegatech LTD2
  • Amazon.com, Inc.1
  • Beget LLC1

Infrastructure traits

  • Hosting 28
  • Anycast 1
  • Mobile 1
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

3 named in public reporting
WIZARD SPIDER

DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.

Conti

Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...

Storm-0501

...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.

MITRE ATT&CK

Hive in ATT&CK

8 distinct techniques

Reporting

Research mentioning Hive

Jul 20
The Record Media

India says allegedly leaked nuclear plant files pose no safety risk | The Record from Recorded Future News

The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.

Jul 17
Cyberveille

Fuite de données : 19 000 fichiers de la centrale nucléaire de Kudankulam exposés par World Leaks | CyberVeille

Jul 17
Theravenfile

KUDANKULAM NUCLEAR POWER PLANT LEAK: AN ACCIDENTAL DISCLOSURE - THE RAVEN FILE

Jul 16
Cysecurity News

Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned - CySecurity News - Latest Information Security and Hacking Incidents

Jul 16
Teiss News

teiss - News - NPCIL denies sensitive data breach at Kudankulam nuclear plant, says leaked files involve only conventional systems

Jul 16
Teiss News

teiss - News - Ransomware group leaks data stolen from India’s largest nuclear plant

Jul 15
Malware News

Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach - Malware News - Malware Analysis, News and Indicators

Jul 15
Teiss News

teiss - News - Exclusive-Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.