Hive was a prolific ransomware-as-a-service operation active until a multinational law-enforcement disruption in January 2023. It is widely tracked as a major cybercriminal extortion group rather than a state actor. Hive conducted double-extortion intrusions, combining data theft with file encryption and operating a leak site to pressure victims that refused to pay. The group was associated with attacks against a broad range of organizations, including healthcare, education, government, and enterprise targets, and was repeatedly cited among the most active ransomware operations of its period. Hive used both Windows and Linux encryptors, including tooling for ESXi and other enterprise server environments, reflecting the broader shift by ransomware actors toward virtualized infrastructure. Reporting also links Hive activity to fast-flux-enabled infrastructure in some campaigns, and to use of malware and tooling common in the ransomware ecosystem such as SystemBC. Tradecraft associated with Hive and overlapping ransomware playbooks includes credential theft, remote access abuse, lateral movement, defense evasion, and rapid enterprise-wide deployment using legitimate administrative mechanisms. Public reporting also places Hive among ransomware groups observed using credential-harvesting utilities and PsExec-style remote execution in broader intrusion chains. Hive’s ecosystem appears to have had personnel and operational overlap with later groups. Hunters International has been described by some researchers as a spin-off or successor with code and infrastructure lineage connected to Hive, although direct continuity claims vary across vendors. Additional reporting has described Hunters International as a precursor to later extortion activity branded as WORLDLEAKS. Former Conti members have also been reported to have splintered into multiple groups including Hive, underscoring the fluid affiliate and operator relationships common across the Russian-speaking ransomware landscape. In January 2023, U.S. and European authorities announced the seizure of Hive infrastructure after infiltrating the operation, making it one of the most prominent law-enforcement disruptions of a ransomware group. Hive nevertheless remains important as a reference point for modern RaaS tradecraft, especially double extortion, cross-platform encryption, and the reuse of shared criminal tooling across affiliate-driven ransomware operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another ransomware operator using Rust.
Referenced as an earlier ransomware lineage connected to Hunters International and indirectly to WorldLeaks.
Mentioned as one of several ransomware families observed using NirSoft tools.
Named as one of the ransomware groups that former Conti members reportedly splintered into after Conti shut down.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.