Hive0163 is a financially motivated extortion threat cluster associated with large-scale data exfiltration and ransomware deployment, including activity linked to Interlock ransomware. The group is characterized by post-compromise operations that emphasize maintaining persistent access, expanding footholds inside victim environments, stealing data, and ultimately deploying ransomware. Reported tooling associated with Hive0163 includes NodeSnake, Interlock RAT, the JunkFiction loader, and a likely AI-assisted PowerShell backdoor known as Slopoly. Hive0163 has also been linked to related tooling or operators associated with Broomstick, Supper, PortStarter, SystemBC, SocksShell, and Rhysida, indicating a broader ecosystem of shared malware development or operational overlap. Hive0163 commonly obtains initial access through ClickFix social engineering, malvertising, and cooperation with initial access brokers including TA569 and TAG-124. In observed intrusions, victims were tricked into executing PowerShell commands that deployed NodeSnake as an initial-stage backdoor. Subsequent payloads included Interlock RAT and Slopoly, along with dual-use tools used to expand access and support lateral movement. Hive0163’s malware framework has been described as multi-language and cross-platform, with implementations in PowerShell, PHP, C/C++, Java, and JavaScript, and support for both Windows and Linux environments. The group’s capabilities include persistent access through scheduled tasks and custom backdoors, remote command execution, reverse shells, SOCKS5 proxy tunneling, payload delivery, network expansion, and data exfiltration. Slopoly in particular functioned as a command-and-control persistence client that collected host information, beaconed to operator infrastructure, polled for commands, executed them through the Windows command interpreter, and returned results. Although Slopoly was described in its own comments as polymorphic, available analysis indicates it was not truly self-modifying; instead, it likely reflects builder-generated variation and AI-assisted development practices intended to accelerate malware creation rather than introduce fundamentally novel tradecraft. Hive0163’s dominant motivation is financial gain through extortion. Its operations combine data theft with ransomware pressure, and its tradecraft shows a strong emphasis on persistence, post-exploitation flexibility, and the use of custom tooling to sustain access long enough to support exfiltration and ransomware execution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated ransomware cluster behind multiple high-profile global attacks involving the Interlock ransomware variant. The group conducts large-scale data theft and ransomware deployments, uses custom tooling for persistence, and leverages ClickFix attacks, malvertising, and reportedly initial access brokers for initial access.
Financially motivated threat actor specializing in post-compromise activity, using custom backdoors for long-term access, data exfiltration, and ransomware deployment. The group was observed using AI-assisted malware Slopoly, as well as NodeSnake and InterlockRAT components, in ransomware intrusions.
Financially motivated e-crime group conducting extortion through large-scale data exfiltration and ransomware, and using Slopoly during post-exploitation to maintain persistence. The group is also associated with a broader malware framework involving NodeSnake, Interlock RAT, JunkFiction loader, and Interlock ransomware.
Financially motivated extortion activity involving large-scale data exfiltration and ransomware operations; observed in an Interlock ransomware intrusion where Slopoly (PowerShell backdoor) was deployed for persistence/C2 and additional backdoors (NodeSnake, InterlockRAT) were used.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.