Hive emerged as a prolific ransomware-as-a-service operation that heavily targeted healthcare and other enterprises, using double extortion to steal data and encrypt systems. Reporting tied the group to intrusions involving phishing, vulnerable RDP, stolen VPN credentials, and possible exploitation of Microsoft Exchange ProxyShell, followed by lateral movement with RDP and WMI, use of Cobalt Strike, shadow-copy deletion, and exfiltration through tools such as 7-Zip and anonymous file-sharing services. The group expanded beyond Windows with Linux and FreeBSD encryptors, including VMware ESXi-focused variants, and was linked to major disruptions at hospitals and other organizations.
At the same time, academics from Kookmin University published a decryption method that exploited weaknesses in Hive’s custom XOR-based file-encryption design, reporting recovery of more than 95% of the master key and decryption of roughly 82% to 98% of affected files without the attackers’ private key. Subsequent public research and proof-of-concept tooling documented Hive version-specific decryptors and analysis resources, while the ransomware operators responded by hardening their malware, including rewriting the Linux ESXi encryptor in Rust and moving ransom-site credentials out of embedded samples and into runtime command-line arguments to reduce analysis and monitoring opportunities.

TTPs, infrastructure, and targeting history in one profile.
18 events from the most recent confirmed update back to the earliest known activity.
The latest visible commit in a Hive-related public repository was labeled "Delete Hive/Hunters directory" and attributed to user rivitna. This reflects ongoing maintenance of public Hive analysis resources.
A file named "Hive_samples.txt" was updated in a public repository. The listing suggests continued curation of Hive sample references for analysis.
A public repository's "hive_v6" folder was updated with the commit message "Update hive6_decrypt_file.py." The update shows ongoing adaptation of public tooling to later Hive versions.
A public repository's "hive_v5" folder was updated with the commit message "Update v5_4_keytable_dec.py." This indicates continued work on tooling for newer Hive variants.
A repository folder named "hive_decrypt" was updated with the commit message "Update sys_windows.go." The listing indicates ongoing development of Hive decryption tooling.
A Hive YARA rule file named "Hive.yar" was updated in a public repository. This reflects publication or maintenance of detection content for Hive samples.
A public repository entry for a Hive v4 demo was added with the commit message "Add files via upload." The listing suggests continued publication of Hive-focused analysis or decryption resources.
The Swiss car dealer attacked in January 2022 appeared on HiveLeaks in February 2022. This reflected Hive's double-extortion practice of naming victims that did not pay.
A public repository entry for a Hive v3 demo was added with the commit message "Update keytab.go." This indicates early public maintenance of Hive-related reverse-engineering or decryption tooling.
In January 2022, one of Europe's largest car dealers in Switzerland suffered a Hive ransomware attack. The victim was later listed on HiveLeaks.
In January 2022, Spain's INCIBE released a report detailing Hive ransomware operations after observing increased activity. The report was cited alongside prior FBI profiling of the group.
Researchers reported that Hive had victimized at least 355 companies as of October 16, 2021. Separate reporting also said 355 enterprises were compromised during the September to December 2021 period based on access to Hive's administrator panel.
In late October 2021, researchers found that Hive had developed new malware tools to encrypt Linux and FreeBSD systems. The discovery highlighted Hive's expansion toward Linux server targeting.
The FBI issued an alert on Hive ransomware in late August 2021, detailing indicators of compromise and tactics, techniques, and procedures. A paper cited the alert date specifically as August 27, 2021.
On August 15, 2021, Hive attacked a non-profit integrated health system, severely disrupting clinical and financial operations at three hospitals in Ohio and West Virginia. The incident caused emergency room diversions, canceled urgent procedures, forced paper-chart operations, and involved theft of patient data for extortion.
Hive ransomware was first seen around June 2021 and emerged as a ransomware-as-a-service operation. Early reporting identified Altus Group as one of its first known victims.
A GitHub project published a proof-of-concept decryptor for Hive versions 5 through 5.2, documenting the malware's file-encryption mechanism and offset brute-forcing approach. The tool supported direct decryption when the sample-specific offset was known and brute force using known file headers when it was obscured.
A team from Kookmin University published a paper describing a method to recover data encrypted by Hive without the attackers' private key. The work exploited weaknesses in Hive's custom encryption scheme and reported recovery of about 95% of the master key, enabling decryption of large portions of victim files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
13 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourcetrendmicro.com
Open sourcenetskope.com
Open sourcelabs.sentinelone.com
Open sourcearxiv.org
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.