Hive0117 is a financially motivated threat actor active since at least late 2021. It is also tracked as Watch Wolf, Ratopak Spider, and UAC-0008. The group primarily targets accounting and finance personnel at organizations, especially in Russia, to obtain access to corporate remote-banking environments and steal funds. Its operations have also affected organizations in Belarus, Kazakhstan, Uzbekistan, Lithuania, and Estonia. Hive0117 commonly uses phishing emails masquerading as routine accounting correspondence, including invoices, reconciliation statements, delivery documentation, and payment notices. Messages may originate from compromised legitimate business mailboxes and deliver password-protected archives containing executable payloads disguised as documents. The group has used the fileless DarkWatchman malware, as well as FMVT RAT in later activity, to profile hosts, execute operator commands, retrieve additional payloads, monitor clipboard data, and support remote access. DarkWatchman campaigns have included keylogging, registry-based fileless persistence and payload storage, encoded PowerShell execution, and process injection. Hive0117 has also deployed remote-access tooling, including HVNC-capable malware, to operate a concealed virtual desktop on a compromised system. The actor monitors for connected smart-card readers and cryptographic tokens used to authorize corporate banking transactions. After compromising an accounting workstation, Hive0117 abuses access to the victim’s legitimate remote-banking system to create fraudulent payment orders. A documented cash-out technique disguises transfers to attacker-controlled accounts as employee payroll payments, helping the transactions resemble routine business activity. Hive0117’s operations are assessed as financially motivated; its geographic origin is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated group targeting finance departments and accountants at Russian organizations to steal money through remote banking systems. Its August–September 2026 campaigns used invoice- and payment-themed phishing emails containing archives with executables, sometimes sent from compromised legitimate mailboxes and password-protected. The group used FMVT RAT and, in at least one incident, deployed LOBSHOT; it had previously used DarkWatchman.
A financially motivated group active since late 2021 that targets accounting staff to obtain access to remote banking systems, intercept payment-signing cryptotokens, and conduct fraudulent transfers disguised as payroll payments.
Financially motivated attacks targeting company accountants to steal money via remote banking systems after infecting victims with DarkWatchman and deploying remote access tools.
Financially motivated threat actor conducting phishing campaigns against corporate finance and accounting departments to steal funds via fraudulent salary-payment transfers using compromised banking access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.