Hive0117 is a financially motivated cybercrime threat actor active since at least late 2021 that specializes in phishing-led intrusions against corporate accounting and finance personnel in order to steal funds from business remote banking systems. The group is known for delivering the DarkWatchman malware family, including fileless variants, through email campaigns that use business-themed lures and password-protected archives disguised as routine accounting or shipping documents. After execution on a victim host, DarkWatchman is used to establish covert access and deploy additional tooling, including keylogging components and remote administration capabilities. Hive0117’s operations focus on compromising workstations used by accountants and finance staff, monitoring keystrokes and clipboard data, and detecting the use of cryptographic tokens associated with corporate banking access. Once suitable banking access is available, the group deploys remote access tools and hidden-virtual-network-computing functionality to operate from the victim environment while reducing user visibility. Observed tooling associated with these intrusions includes DarkWatchman, LiteManager, BitRAT, and malware with hVNC capability. The actor’s objective is direct theft from victim organizations rather than espionage. A notable tradecraft pattern is the abuse of legitimate corporate online banking sessions from compromised systems so that transactions appear normal to fraud controls. In more recent activity, Hive0117 shifted from straightforward transfers to fraudulent payroll-register payments designed to resemble ordinary salary disbursements while routing funds to attacker-controlled accounts. Victimology indicates a strong emphasis on Russian organizations, especially finance departments, with additional victims identified in Belarus, Kazakhstan, and Uzbekistan. Reported affected sectors include telecommunications, industrial enterprises, trade, online retail, and manufacturing. Hive0117 has also been observed targeting users in other post-Soviet and Baltic states. The group’s origin remains unknown.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated attacks targeting company accountants to steal money via remote banking systems after infecting victims with DarkWatchman and deploying remote access tools.
Financially motivated threat actor conducting phishing campaigns against corporate finance and accounting departments to steal funds via fraudulent salary-payment transfers using compromised banking access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.