Last seven days
- First activity
- Sep 20, 2026
- Last activity
- Sep 24, 2026
- Feed role
- C2 / Distribution
- Host form
- 4 IP / 1 hostnames
Hive was an affiliate-based ransomware-as-a-service operation first observed in June 2021.
Profile source: Mallory opens in a new tabHive
Hive was an affiliate-based ransomware-as-a-service operation first observed in June 2021. Affiliates targeted organizations across multiple sectors, including healthcare and software, using phishing attachments, exposed or vulnerable Remote Desktop Protocol services, and compromised VPN credentials for access. The operation employed double extortion: operators exfiltrated victim data, encrypted systems and files, and threatened public disclosure when payment was not made.
Hive encryptors were developed for Windows, Linux, FreeBSD, and VMware ESXi-oriented environments. Earlier versions were written in Go, while a major 2022 Windows variant was rewritten in Rust and used Curve25519 ECDH and XChaCha20-Poly1305 cryptographic operations. The malware supported selective local and network encryption, process and service termination, deletion of backup and shadow-copy data, disabling of recovery mechanisms, and attempts to impair endpoint security tooling. Hive affiliates also used reconnaissance, credential-access, remote-administration, and enterprise deployment tooling to expand attacks across victim networks.
U.S. law enforcement infiltrated Hive infrastructure beginning in 2022, provided decryption keys to victims, and publicly disrupted the operation in January 2023. Hive was associated with ransomware affiliate activity attributed in U.S. criminal proceedings to Mikhail Pavlovich Matveev, also known as Wazawaka and Boriselcin.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 351dc84d3ce09953cb240b9674cf19b5e51557e1153e24c0e0424f095d89fd67 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 d1a9af107653b79fa2c10cc852c3ed6c4f37574277ccbc2bec97c1eaf3565cd0 2a018987d8fb348a3e5e05595afbcd4bfa5631b6e0df83219390cca2e5ea758a bed76b617a0dd97871dccc90d1b52c1760be066aabda67990308b22c29877a16 46fa26be6717553ade163809f26eb6f21357b64ebab3e92f53228fd38fe17b15 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e bdeeb6376f243f3a0081013593fdff3c2db1b5c4b6885fd761bd3906c18673ba dbc0d7546b385d189e70be289d0b101516a790d5a1c7380bbe35193d4fe28aee Reported operators
Hive ransomware is only about one year old, having been first observed in June 2021, but it has grown into one of the most prevalent ransomware payloads in the ransomware as a service (RaaS) ecosystem.
Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.
DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.
Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
Exploited software
MITRE ATT&CK
Reporting
Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.
The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.