Microsoft reported that the Hive ransomware operation deployed a heavily reworked variant rewritten from Go to Rust, introducing a more complex encryption scheme and stealth improvements that initially helped some samples avoid detection. Analysts said the new build was uncovered after unusual .key files lacked the victim identifier normally associated with Hive, leading to the discovery of multiple related samples. The malware now requires ransom-site credentials through the command line, decrypts strings at runtime to hinder analysis, and uses updated cryptography built on Curve25519 ECDH and XChaCha20-Poly1305.
The updated payload also attempts to maximize impact by stopping security, backup, database, and business application services before launching recovery-disruption commands to remove shadow copies and backups. Microsoft said Hive continued to operate as a ransomware-as-a-service threat seen in intrusions affecting sectors including healthcare and software, with activity linked to affiliate DEV-0237, now tracked as Pistachio Tempest. The company published indicators of compromise, detections, and mitigation guidance to help defenders identify and contain Hive-related attacks.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft Threat Intelligence published analysis of the new Hive variant, describing its Rust rewrite, runtime string decryption, revised cryptography, and recovery-disabling behavior. Microsoft also released indicators of compromise, detections, and defensive guidance for customers.
Microsoft said it first observed the new Hive variant in its threat data on February 22, 2022. The variant represented a major overhaul, including a migration from Go to Rust and updated encryption behavior.
Microsoft reported that the new Hive ransomware variant was first uploaded to VirusTotal on February 21, 2022, marking an early public sample of the overhauled malware.
Microsoft said Hive ransomware was first observed in June 2021 and went on to become one of the more prevalent ransomware-as-a-service payloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
docs.microsoft.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourcedocs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.