Defense Evasion
- GMER
- PCHunter
Hive was a ransomware-as-a-service (RaaS) operation first observed in June 2021.
Profile source: Mallory opens in a new tabHive
Hive was a ransomware-as-a-service (RaaS) operation first observed in June 2021. It used an affiliate model in which affiliates obtained and expanded access to victim environments while operators supported ransom negotiations and operated a data-leak site. Hive conducted double-extortion attacks: affiliates exfiltrated victim data, encrypted systems, and threatened public disclosure when payment demands were not met. The operation affected organizations across multiple sectors, notably healthcare, software, and critical infrastructure.
Hive affiliates used phishing attachments, exposed or vulnerable Remote Desktop Protocol services, compromised VPN credentials, and exploitation of unpatched Microsoft Exchange ProxyShell vulnerabilities for access. Intrusions included Active Directory and network reconnaissance, credential theft, use of Cobalt Strike, lateral movement through RDP and administrative deployment mechanisms, and data exfiltration before encryption. Hive-associated activity also used IPfuscation loaders to conceal Cobalt Strike stagers in encoded address-like strings.
Hive ransomware targeted Windows systems and later added Golang-based Linux and FreeBSD encryptors, reflecting an emphasis on server and virtualized environments, including VMware ESXi. Earlier variants were written in Go; a later major variant was rewritten in Rust. The malware stopped security, backup, database, and enterprise services; impaired recovery by deleting shadow copies and backup data; cleared event logs; and attempted to disable Microsoft Defender and other defenses. It used configurable encryption behavior and cryptographic designs that evolved over time.
Law enforcement infiltrated Hive infrastructure beginning in 2022, provided decryption keys to victims, and seized the operation's infrastructure and leak site in January 2023. U.S. prosecutors have alleged that ransomware affiliate Mikhail Matveev participated in a Hive-related ransomware conspiracy; this is an allegation, not a judicial finding of guilt.
Reported operators
Hive ransomware is only about one year old, having been first observed in June 2021, but it has grown into one of the most prevalent ransomware payloads in the ransomware as a service (RaaS) ecosystem.
Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.
DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.
Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
Exploited software
MITRE ATT&CK
Reporting
Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.
The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.