Researchers reported that Hive ransomware affiliates used a new obfuscation method dubbed "IPfuscation" to conceal malware payloads inside 64-bit Windows loaders. The technique stores shellcode as arrays of ASCII-formatted network identifiers—primarily IPv4 addresses—which are converted at runtime through Windows string-to-address APIs and then executed to launch a Cobalt Strike Beacon stager. Analysts observed execution methods including direct system calls and callback abuse through EnumUILanguagesA, making the loaders harder to detect with traditional static signatures.
Sentinel Labs also identified related variants that encoded payloads as IPv6 addresses, UUIDs, base64-encoded UUIDs, and MAC addresses, along with a Golang loader that shared development artifacts suggesting a common author. The activity aligned with known Hive intrusion tradecraft, including use of PowerShell, BAT scripts, ADFind, SharpView, BloodHound, SharpHashSpray, SharpDomainSpray, Rubeus, Group Policy Objects, and scheduled tasks. Researchers said defenders should prioritize behavioral detection, endpoint telemetry correlation, and broader security analytics over signature-only approaches, and they published malware hashes, C2 indicators, and YARA rules tied to the IPfuscation family.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
SC Media reported on Sentinel Labs' findings that Hive used the IPfuscation technique to conceal payloads that ultimately downloaded Cobalt Strike beacons. The article also noted observed IPv6, MAC, and UUID variants and the recommendation for behavioral and AI-assisted detection.
BleepingComputer reported that researchers had described IPfuscation as a new malware obfuscation technique observed in a Hive ransomware incident. The coverage highlighted that static signatures alone were insufficient and emphasized behavioral and broader endpoint detection approaches.
SentinelOne publicly released a report detailing IPfuscation, associated malware samples, related Hive intrusion tradecraft, and detection content including hashes, infrastructure, and YARA rules. The report described how the loaders reconstructed and executed Cobalt Strike Beacon payloads on 64-bit Windows systems.
The analysis found related loader variants that reconstructed payloads from other encoded formats, including IPv6 addresses, UUIDs, base64-encoded UUIDs, and MAC addresses. Execution methods included EnumUILanguagesA callbacks, direct syscalls via Hell's Gate, and EnumWindows callbacks.
Sentinel Labs identified a novel obfuscation method used in a Hive ransomware incident, in which payload data was disguised as ASCII-formatted IPv4 addresses and reconstructed into shellcode to deliver a Cobalt Strike stager. The researchers named the technique 'IPfuscation.'
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 64 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
scmagazine.com
Open sourcebleepingcomputer.com
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.