Overview

Platforms: —
Variants: —
Extensions: —
ATT&CK software: —
Initial access: External Remote Services · Exploit Public-Facing Application · Spearphishing Attachment
Top countries: —
Observed sectors: —
Tracked victims: 201

Attribution

Mikhail Matveev VERIFIED
Alleged Hive participant
U.S. authorities charged Matveev with participating in conspiracies involving Hive ransomware and alleged that he and Hive co-conspirators deployed the ransomware against victims.

Affiliates

No affiliate information available.

Activity

Recent Observations

Hive infrastructure disrupted
January 2023
Law-enforcement action
International law enforcement seized servers and websites used by Hive, disrupting the operation's ability to attack and extort victims.
More than 1,300 organizations victimized
November 2022
Ransomware activity
U.S. authorities reported that Hive had victimized more than 1,300 organizations worldwide and received approximately $100 million in ransom payments.
FBI covert infiltration begins
July 2022
Law-enforcement operation
The FBI penetrated Hive infrastructure and began obtaining decryption keys that were subsequently provided to victims.

TTPs

ATT&CK coverage: 7 techniques · 4 tactics
T1133 External Remote Services
VERIFIED
Initial Access
Hive affiliates gained initial access through RDP, VPN and other externally accessible remote services.
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
Hive actors exploited vulnerabilities in internet-facing Microsoft Exchange and Fortinet infrastructure.
T1566.001 Spearphishing Attachment
VERIFIED
Initial Access
Hive affiliates distributed phishing emails containing malicious attachments.
Show more TTPs (4)
T1059 Command and Scripting Interpreter
VERIFIED
Execution
Hive actors used command-line tools and PowerShell during ransomware operations.
T1490 Inhibit System Recovery
VERIFIED
Impact
Hive stopped Volume Shadow Copy services and removed existing shadow copies before encryption.
T1070 Indicator Removal
VERIFIED
Defense Evasion
Hive actors deleted Windows System, Security and Application event logs.
T1112 Modify Registry
VERIFIED
Defense Evasion
Hive modified registry settings to disable Windows Defender and other security controls.

Victims

Newfoundland and Labrador Health Care System CONFIRMED
October 2021 Canada Healthcare
Healthcare organization in Canada.

CVEs

Fortinet — FortiOS
Hive actors exploited this vulnerability to bypass multifactor authentication and gain access to FortiOS systems.
Associated since: June 2021
Microsoft — Exchange Server
Hive actors exploited this ProxyShell vulnerability against exposed Microsoft Exchange servers for initial access.
Associated since: June 2021
Microsoft — Exchange Server
Hive actors exploited this ProxyShell vulnerability against exposed Microsoft Exchange servers.
Associated since: June 2021
Show more CVEs (1)
Microsoft — Exchange Server
Hive actors exploited this ProxyShell vulnerability as part of attacks against Microsoft Exchange infrastructure.
Associated since: June 2021

Infrastructure

Hive leak site
Tor-hosted infrastructure used to publish victim data and support Hive's double-extortion model.
Hive affiliate panel
Backend servers and communication infrastructure supported coordination between Hive operators and ransomware affiliates.

Timeline

2023-01
International disruption
U.S., German and Dutch authorities seized Hive servers and websites, disrupting the ransomware operation.
2022-11
More than 1,300 victims reported
U.S. authorities reported more than 1,300 victim organizations and approximately $100 million in ransom payments.
2022-07
FBI infiltrates Hive infrastructure
The FBI covertly penetrated Hive's network and began obtaining decryption keys for active and previous victims.
Show more events (2)
2021-10
Newfoundland and Labrador healthcare attack
Hive compromised systems supporting the Newfoundland and Labrador healthcare environment.
2021-06
Hive operation emerges
Hive ransomware activity began targeting organizations through a ransomware-as-a-service model.

Sources