Skip to content

Hive

Hive was a ransomware-as-a-service (RaaS) operation first observed in June 2021.

Profile source: Mallory opens in a new tab

Hive

Family profile

Hive was a ransomware-as-a-service (RaaS) operation first observed in June 2021. It used an affiliate model in which affiliates obtained and expanded access to victim environments while operators supported ransom negotiations and operated a data-leak site. Hive conducted double-extortion attacks: affiliates exfiltrated victim data, encrypted systems, and threatened public disclosure when payment demands were not met. The operation affected organizations across multiple sectors, notably healthcare, software, and critical infrastructure.

Hive affiliates used phishing attachments, exposed or vulnerable Remote Desktop Protocol services, compromised VPN credentials, and exploitation of unpatched Microsoft Exchange ProxyShell vulnerabilities for access. Intrusions included Active Directory and network reconnaissance, credential theft, use of Cobalt Strike, lateral movement through RDP and administrative deployment mechanisms, and data exfiltration before encryption. Hive-associated activity also used IPfuscation loaders to conceal Cobalt Strike stagers in encoded address-like strings.

Hive ransomware targeted Windows systems and later added Golang-based Linux and FreeBSD encryptors, reflecting an emphasis on server and virtualized environments, including VMware ESXi. Earlier variants were written in Go; a later major variant was rewritten in Rust. The malware stopped security, backup, database, and enterprise services; impaired recovery by deleting shadow copies and backup data; cleared event logs; and attempted to disable Microsoft Defender and other defenses. It used configurable encryption behavior and cryptographic designs that evolved over time.

Law enforcement infiltrated Hive infrastructure beginning in 2022, provided decryption keys to victims, and seized the operation's infrastructure and leak site in January 2023. U.S. prosecutors have alleged that ransomware affiliate Mikhail Matveev participated in a Hive-related ransomware conspiracy; this is an allegation, not a judicial finding of guilt.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Post Exploitation
  • Reconnaissance

Operational record

1
YARA rules
2
Ransom notes
8
Negotiations
3
Leak sites
0 available

Defense Evasion

  • GMER
  • PCHunter

Discovery Enum

  • Advanced IP Scanner
  • Bloodhound
  • SoftPerfect NetScan

Exfiltration

  • MEGA
  • PrivatLab
  • RClone
  • Sendspace
  • UFile

LOLBAS

  • BCDEdit
  • BITSAdmin
  • WMIC
  • Windows Event Utility (wevtutil)

Offsec

  • Cobalt Strike
  • Impacket
  • Metasploit
  • Meterpreter
  • PowerShell Empire

RMM Tools

  • Atera
  • ScreenConnect
  • Splashtop

Reported operators

Threat actors

5 named in public reporting
fin12

Hive ransomware is only about one year old, having been first observed in June 2021, but it has grown into one of the most prevalent ransomware payloads in the ransomware as a service (RaaS) ecosystem.

Wazawaka

Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.

WIZARD SPIDER

DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.

Conti

Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...

Storm-0501

...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.

Exploited software

Vulnerabilities linked to Hive

7 CVEs

MITRE ATT&CK

Hive in ATT&CK

65 distinct techniques

Techniques

65 techniques
T1040 Network Sniffing T1486 Data Encrypted for Impact T1497 Virtualization/Sandbox Evasion T1059 Command and Scripting Interpreter T1070 Indicator Removal T1490 Inhibit System Recovery T1129 Shared Modules T1562 Impair Defenses T1489 Service Stop T1027 Obfuscated Files or Information T1134 Access Token Manipulation T1059.003 Windows Command Shell T1569 System Services T1041 Exfiltration Over C2 Channel T1657 Financial Theft T1027.002 Software Packing T1007 System Service Discovery T1136 Create Account T1021.002 SMB/Windows Admin Shares T1480 Execution Guardrails T1135 Network Share Discovery T1021.001 Remote Desktop Protocol T1562.001 Disable or Modify Tools T1136.001 Local Account T1140 Deobfuscate/Decode Files or Information T1562.009 Safe Mode Boot T1197 BITS Jobs T1105 Ingress Tool Transfer T1080 Taint Shared Content T1547 Boot or Logon Autostart Execution T1485 Data Destruction T1021 Remote Services T1037 Boot or Logon Initialization Scripts T1112 Modify Registry T1560 Archive Collected Data T1560.001 Archive via Utility T1484.001 Group Policy Modification T1570 Lateral Tool Transfer T1027.009 Embedded Payloads T1484 Domain or Tenant Policy Modification T1037.003 Network Logon Script T1529 System Shutdown/Reboot T1049 System Network Connections Discovery T1090 Proxy T1564 Hide Artifacts T1070.004 File Deletion T1016 System Network Configuration Discovery T1218 System Binary Proxy Execution T1057 Process Discovery T1071 Application Layer Protocol T1190 Exploit Public-Facing Application T1219 Remote Access Tools T1082 System Information Discovery T1036 Masquerading T1091 Replication Through Removable Media T1068 Exploitation for Privilege Escalation T1568.001 Fast Flux DNS T1584 Compromise Infrastructure T1078 Valid Accounts: Remote Desktop Protocol T1566.001 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell T1070.001 Indicator Removal: Clear Windows Event Logs T1003.001 OS Credential Dumping: LSASS Memory T1046 Network Service Discovery T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Reporting

Research mentioning Hive

Aug 12
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RansomEXX

Researchers identified a Linux-targeting variant of RansomEXX, marking an expansion of the ransomware family beyond its previously known Windows builds. The malware is a 64-bit ELF executable that encrypts files with AES-256 in ECB mode and appends an RSA-4096-encrypted AES key to each file, using cryptographic functions from the mbedtls library. Analysis found the Linux sample shares code structure, encryption logic, and ransom note language with earlier Windows PE versions, indicating it is a Linux build of the same ransomware family. The sample appears to have been used in highly targeted intrusions rather than broad campaigns. Researchers found hardcoded victim-specific identifiers embedded in the binary, including the encrypted file extension and extortion contact details, and noted a likely connection to a ransomware attack on a Brazilian government institution because of a nearly identical ransom note. Unlike many mature ransomware strains, the Linux variant lacked common supporting capabilities such as command-and-control communication, process killing, and anti-analysis features, suggesting operators relied on manual targeting and deployment.

Jul 20
The Record Media

India says allegedly leaked nuclear plant files pose no safety risk | The Record from Recorded Future News

The cyber extortion group World Leaks published a cache of files allegedly tied to India’s Kudankulam Nuclear Power Plant after claiming it breached the internal network of contractor Reliance Group. Reporting says roughly 19,000 files totaling about 14.3 GB, labeled KKNP, were exposed as part of a much larger dump of about 858,000 Reliance-linked files. The leaked material reportedly includes blueprints, supplier details, inspection records, equipment reviews, insurance documents, and project documentation connected to Kudankulam Units 3 and 4, with some documents reviewed by Reuters dated from 2016 to mid-2025, though authenticity has not been independently verified. NPCIL denied that nuclear safety or security systems were compromised, saying the exposed data concerned only conventional balance-of-plant service facilities already covered under a public tender. Reliance acknowledged a partial breach involving a server hosted by Yotta and said Indian government authorities and law enforcement were notified, while Yotta said it detected suspicious activity on May 29 and blocked suspected ransomware execution but could not confirm subsequent breach claims. Despite the denial of impact to sensitive nuclear systems, outside researchers and experts warned that the leaked blueprints, supplier information, and related records could still create security risks for critical infrastructure.

Jul 17
Cyberveille

Fuite de données : 19 000 fichiers de la centrale nucléaire de Kudankulam exposés par World Leaks | CyberVeille

Jul 17
Theravenfile

KUDANKULAM NUCLEAR POWER PLANT LEAK: AN ACCIDENTAL DISCLOSURE - THE RAVEN FILE

Jul 16
Cysecurity News

Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned - CySecurity News - Latest Information Security and Hacking Incidents

Jul 16
Teiss News

teiss - News - NPCIL denies sensitive data breach at Kudankulam nuclear plant, says leaked files involve only conventional systems

Jul 16
Teiss News

teiss - News - Ransomware group leaks data stolen from India’s largest nuclear plant

Jul 15
Malware News

Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach - Malware News - Malware Analysis, News and Indicators

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.