Hive was a ransomware family and ransomware-as-a-service operation active from 2021 until a major international law-enforcement disruption in January 2023. It became one of the most prolific enterprise-focused ransomware threats of its period and was associated with double-extortion activity in which operators encrypted victim systems and threatened to publish stolen data. Hive was repeatedly linked to attacks against healthcare and other critical sectors, and public reporting and government advisories highlighted it as a significant risk to hospitals and broader enterprise environments.
Hive is primarily known as a Windows ransomware family, but the operation also fielded Linux encryptors for server-side targeting, including ESXi environments, reflecting the broader shift by major ransomware groups toward virtualization and Linux-based infrastructure. Research comparing ESXi lockers found no obvious code similarity between Hive’s ESXi encryptor and Babuk-derived Linux lockers used by some other ransomware families, indicating Hive maintained a distinct implementation in that area.
Operational reporting tied Hive-associated activity to common hands-on-keyboard ransomware tradecraft rather than a unique initial access mechanism. Observed and reported intrusion patterns associated with Hive deployments included abuse of compromised remote access, credential theft, lateral movement with administrative tooling, data exfiltration, and defense evasion prior to encryption. Hive-related attacks have also been associated with resilient infrastructure techniques such as fast flux. Multiple reports describe affiliates or related operators switching among ransomware payloads over time, with Hive appearing in the toolsets of broader cybercriminal ecosystems alongside families such as Ryuk, Conti, BlackCat, and LockBit.
The Hive ecosystem has been linked in public reporting to Russian-speaking cybercrime actors, including allegations involving Mikhail Pavlovich Matveev in development or deployment activity. After the January 2023 takedown, subsequent reporting frequently discussed Hunters International as a likely successor or spin-off due to code similarities and claimed acquisition of Hive-related assets, although the exact continuity between the operations has been debated.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DEV-0237 heavily used Ryuk and Conti payloads from Trickbot LLC/DEV-0193, then Hive payloads more recently.
Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
file1.bat : a batch file designed to set up the system with autologon as the newly-created administrative user AdminBac, reboot into Safe Mode ... file2.bat : a second batch file, executed in Safe Mode via a registry key, designed to unpack the ransomware binary from the encrypted archive
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
65 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another ransomware family using Rust.
Ransomware family/group referenced as the earlier lineage behind Hunters International and, indirectly, WorldLeaks. Mentioned for background context on group evolution.
Ransomware family mentioned as one of the families observed using NirSoft tools.
A ransomware family behaviorally similar to LockBit in this evaluation because both generate encryption-heavy file activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.