Hive0137 is a tracked cybercriminal intrusion set associated with email-borne malware delivery and initial-access operations that can precede ransomware deployment. Activity observed in early 2024 shows the actor running phishing campaigns in English using common business lures such as invoices, reimbursements, budget reviews, reports, and meeting materials. The group adapted delivery methods over time, including experimentation with spreadsheet attachments containing malicious UNC-path links that triggered staged script retrieval and execution, ultimately delivering DarkGate. Later activity included delivery of PikaBot through malicious HTML that abused the search-ms protocol and staged payloads from remote SMB shares. Hive0137 has been observed using new payloads and crypters and shifting attachment formats as part of its delivery tradecraft. The actor’s operations are assessed as initial-access activity that can enable downstream ransomware attacks. Observed payload chains and overlap in timing and techniques place Hive0137 in a broader ecosystem of email distributors and malware loaders linked to ransomware intrusion activity, including campaigns involving DarkGate and PikaBot; PikaBot infections have commonly preceded Black Basta ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.