Hive was a financially motivated ransomware-as-a-service (RaaS) operation active from June 2021 until its infrastructure was dismantled in a joint FBI and Europol operation in January 2023. It operated a double-extortion model: affiliates compromised organizational networks, stole data, encrypted systems, and threatened publication through the HiveLeaks leak site if victims did not pay. Hive recruited affiliates, including operators with pre-existing corporate-network access, and provided ransomware-build generation, negotiation support, and revenue sharing. Hive affiliates gained access through exposed or vulnerable remote services, compromised VPN credentials, phishing attachments, callback-phishing activity, and exploitation of unpatched Microsoft Exchange ProxyShell vulnerabilities. Post-compromise activity included Cobalt Strike, credential dumping, Active Directory and network reconnaissance, password spraying, lateral movement using stolen administrator credentials and remote-management tooling, data exfiltration, and deployment through Group Policy or scheduled tasks. Operators also used obfuscated Cobalt Strike loaders employing IPv4, IPv6, UUID, and MAC-address-formatted payload encodings, a technique known as IPfuscation. Hive ransomware was initially Windows-focused and written in Go, with later Linux, FreeBSD, and VMware ESXi-targeting variants. The operation disabled or terminated security, backup, database, and file-locking services; deleted shadow copies; enumerated local and network drives; and performed concurrent encryption to accelerate impact. Hive repeatedly targeted healthcare organizations, including hospitals and health-plan providers, causing significant operational disruption. It also targeted manufacturing and legal-sector organizations. Hive is also referred to as Hive ransomware and Hive ransomware actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE-2021-31207 (Base Score: 7.2) Microsoft Exchange Server Security Feature Bypass Vulnerability... During the investigation, we found specific exploitation evidence of these CVEs... which allowed the adversary to deploy webshells successfully on the compromised server.
CVE-2021-34473 (Base Score: 9.8) Microsoft Exchange Server Remote Code Execution Vulnerability... During the investigation, we found specific exploitation evidence of these CVEs... which allowed the adversary to deploy webshells successfully on the compromised server. | First, the attacker exploited multiple Exchange security vulnerabilities, referred to as ProxyShell... ProxyShell involves a set of three separate security flaws and allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange Server.
CVE-2021-34523 (Base Score: 9.8) Microsoft Exchange Server Elevation of Privilege Vulnerability... During the investigation, we found specific exploitation evidence of these CVEs... which allowed the adversary to deploy webshells successfully on the compromised server.
124 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Defunct ransomware group discussed as having TTP similarities to Play and as the suspected predecessor of Hunters International.
Mentioned as a competing ransomware group that relied on access brokers.
Named as one of multiple ransomware groups operating data leak sites and listing fresh victims.
Mentioned only as another ransomware operator using Rust.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.