Defense Evasion
- GMER
- PCHunter
Hive was a ransomware family and ransomware-as-a-service operation active from 2021 until a major international law-enforcement disruption in January 2023.
Profile source: Mallory opens in a new tabHive
Hive was a ransomware family and ransomware-as-a-service operation active from 2021 until a major international law-enforcement disruption in January 2023. It became one of the most prolific enterprise-focused ransomware threats of its period and was associated with double-extortion activity in which operators encrypted victim systems and threatened to publish stolen data. Hive was repeatedly linked to attacks against healthcare and other critical sectors, and public reporting and government advisories highlighted it as a significant risk to hospitals and broader enterprise environments.
Hive is primarily known as a Windows ransomware family, but the operation also fielded Linux encryptors for server-side targeting, including ESXi environments, reflecting the broader shift by major ransomware groups toward virtualization and Linux-based infrastructure. Research comparing ESXi lockers found no obvious code similarity between Hive’s ESXi encryptor and Babuk-derived Linux lockers used by some other ransomware families, indicating Hive maintained a distinct implementation in that area.
Operational reporting tied Hive-associated activity to common hands-on-keyboard ransomware tradecraft rather than a unique initial access mechanism. Observed and reported intrusion patterns associated with Hive deployments included abuse of compromised remote access, credential theft, lateral movement with administrative tooling, data exfiltration, and defense evasion prior to encryption. Hive-related attacks have also been associated with resilient infrastructure techniques such as fast flux. Multiple reports describe affiliates or related operators switching among ransomware payloads over time, with Hive appearing in the toolsets of broader cybercriminal ecosystems alongside families such as Ryuk, Conti, BlackCat, and LockBit.
The Hive ecosystem has been linked in public reporting to Russian-speaking cybercrime actors, including allegations involving Mikhail Pavlovich Matveev in development or deployment activity. After the January 2023 takedown, subsequent reporting frequently discussed Hunters International as a likely successor or spin-off due to code similarities and claimed acquisition of Hive-related assets, although the exact continuity between the operations has been debated.
Reported operators
DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.
Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
MITRE ATT&CK
Reporting
The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.