Overview
Platforms:
—
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
External Remote Services · Exploit Public-Facing Application · Spearphishing Attachment
Top countries:
—
Observed sectors:
—
Tracked victims:
201
Attribution
Mikhail Matveev
VERIFIED
Alleged Hive participant
U.S. authorities charged Matveev with participating in conspiracies involving Hive ransomware and alleged that he and Hive co-conspirators deployed the ransomware against victims.
Affiliates
No affiliate information available.
Activity
Recent Observations
Hive infrastructure disrupted
January 2023
Law-enforcement action
International law enforcement seized servers and websites used by Hive, disrupting the operation's ability to attack and extort victims.
More than 1,300 organizations victimized
November 2022
Ransomware activity
U.S. authorities reported that Hive had victimized more than 1,300 organizations worldwide and received approximately $100 million in ransom payments.
FBI covert infiltration begins
July 2022
Law-enforcement operation
The FBI penetrated Hive infrastructure and began obtaining decryption keys that were subsequently provided to victims.
TTPs
ATT&CK coverage:
7 techniques
· 4 tactics
T1133
External Remote Services
VERIFIEDInitial Access
Hive affiliates gained initial access through RDP, VPN and other externally accessible remote services.
T1190
Exploit Public-Facing Application
VERIFIEDInitial Access
Hive actors exploited vulnerabilities in internet-facing Microsoft Exchange and Fortinet infrastructure.
T1566.001
Spearphishing Attachment
VERIFIEDInitial Access
Hive affiliates distributed phishing emails containing malicious attachments.
Show more TTPs (4)
T1059
Command and Scripting Interpreter
VERIFIEDExecution
Hive actors used command-line tools and PowerShell during ransomware operations.
T1490
Inhibit System Recovery
VERIFIEDImpact
Hive stopped Volume Shadow Copy services and removed existing shadow copies before encryption.
T1070
Indicator Removal
VERIFIEDDefense Evasion
Hive actors deleted Windows System, Security and Application event logs.
T1112
Modify Registry
VERIFIEDDefense Evasion
Hive modified registry settings to disable Windows Defender and other security controls.
Victims
Newfoundland and Labrador Health Care System
CONFIRMED
Healthcare organization in Canada.
CVEs
Fortinet
— FortiOS
Hive actors exploited this vulnerability to bypass multifactor authentication and gain access to FortiOS systems.
Associated since:
June 2021
Microsoft
— Exchange Server
Hive actors exploited this ProxyShell vulnerability against exposed Microsoft Exchange servers for initial access.
Associated since:
June 2021
Microsoft
— Exchange Server
Hive actors exploited this ProxyShell vulnerability against exposed Microsoft Exchange servers.
Associated since:
June 2021
Show more CVEs (1)
Microsoft
— Exchange Server
Hive actors exploited this ProxyShell vulnerability as part of attacks against Microsoft Exchange infrastructure.
Associated since:
June 2021
Infrastructure
Hive leak site
Tor-hosted infrastructure used to publish victim data and support Hive's double-extortion model.
Hive affiliate panel
Backend servers and communication infrastructure supported coordination between Hive operators and ransomware affiliates.
Timeline
2023-01
International disruption
U.S., German and Dutch authorities seized Hive servers and websites, disrupting the ransomware operation.
2022-11
More than 1,300 victims reported
U.S. authorities reported more than 1,300 victim organizations and approximately $100 million in ransom payments.
2022-07
FBI infiltrates Hive infrastructure
The FBI covertly penetrated Hive's network and began obtaining decryption keys for active and previous victims.
Show more events (2)
2021-10
Newfoundland and Labrador healthcare attack
Hive compromised systems supporting the Newfoundland and Labrador healthcare environment.
2021-06
Hive operation emerges
Hive ransomware activity began targeting organizations through a ransomware-as-a-service model.
Sources
#StopRansomware: Hive Ransomware
CISA / FBI / HHS
U.S. Department of Justice Disrupts Hive Ransomware Variant
U.S. Department of Justice
Show more sources (3)
Russian National Charged with Ransomware Attacks Against Critical Infrastructure
U.S. Department of Justice
Overview: Cyberattack on the Newfoundland and Labrador Health Care System
Government of Newfoundland and Labrador
Incident report