Hive0117 is a financially motivated intrusion set active since at least late 2021 that is best known for phishing-led theft from corporate remote banking systems. The group primarily targets accounting and finance personnel, using business-themed lures and password-protected archives to deliver DarkWatchman, a fileless remote access trojan closely associated with its operations. After initial compromise, Hive0117 has deployed additional tooling including keylogging components, remote administration utilities, and hidden virtual desktop capabilities to monitor victims, maintain access, and conduct fraudulent banking activity from compromised endpoints. The actor’s tradecraft centers on social engineering against financial departments. Observed lures impersonate routine accounting and administrative documents such as invoices, reconciliation statements, shipping paperwork, and other finance-related correspondence. DarkWatchman infections have been used to download a keylogger that captures keystrokes, monitors clipboard contents, and detects connection of cryptographic tokens commonly used for corporate banking access. Once banking access is available, the group conducts follow-on activity from the victim machine so transactions appear legitimate. Reported monetization includes fraudulent transfers disguised as payroll or salary payments to attacker-controlled accounts. Hive0117 has heavily targeted Russian organizations and has also victimized companies in Belarus, Kazakhstan, and Uzbekistan. Reported victims span multiple sectors, with a persistent emphasis on corporate finance functions rather than a single vertical. Additional reporting has linked Hive0117 to phishing and malware delivery against Russian aerospace and defense-adjacent entities, including use of DarkWatchman in campaigns against strategically important Russian organizations. Some reporting has described Hive0117 as aligned with Ukrainian interests in operations against Russian targets, while other reporting states the group’s origin remains unknown and assesses its activity as primarily criminal rather than part of the Russia-Ukraine cyber conflict. The strongest consistent characterization is that Hive0117 is a financially motivated actor specializing in phishing, credential and banking-access theft, covert remote control, and post-compromise fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated attacks targeting company accountants to steal money via remote banking systems after infecting victims with DarkWatchman and deploying remote access tools.
Financially motivated threat actor conducting phishing campaigns against corporate finance and accounting departments to steal funds via fraudulent salary-payment transfers using compromised banking access.
Ukraine-aligned intrusion set conducting spearphishing campaigns against Russian aerospace targets and deploying DarkWatchman malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.