Hive0131 is a financially motivated cybercrime group assessed to likely originate from South America and to operate primarily across Latin America. The group is associated with phishing-led malware delivery campaigns that distribute commodity malware, including information stealers and remote access trojans. Reported activity includes campaigns targeting organizations and users in Latin America, including Colombia, using social-engineering lures themed around invoices or legal matters. Hive0131 has been linked to the use of VMDetectLoader, a modular .NET loader that performs virtual-machine checks and supports in-memory payload delivery. Observed tradecraft includes phishing as an initial access vector, PowerShell-based execution, reflective loading of .NET assemblies, and process hollowing into legitimate Windows processes for defense evasion and post-compromise execution. Campaigns associated with this cluster have delivered commodity payloads such as PURELOGS, a .NET infostealer capable of stealing browser credentials, cookies, autofill data, payment-card data, cryptocurrency-wallet data, and information from numerous desktop applications, as well as DCRat in other operations. Attribution of specific PURELOGS activity to Hive0131 is low confidence where the principal linkage is shared loader usage and code-language similarities. High-confidence characterization supports Hive0131 as a South American, financially motivated threat group focused on phishing-driven malware distribution in Latin America rather than as a confirmed operator of a unique malware family or ransomware program.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Low-confidence attribution link via use of VMDetectLoader in a PURELOGS stealer campaign.
Hive0131 conducts phishing campaigns in Latin America, delivering commodity malware such as DCRat for information theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.