Description Summary
Hive was a major ransomware-as-a-service active from June 2021 until its infrastructure was disrupted by a coordinated FBI/Europol operation in January 2023. The FBI had infiltrated Hive's network in mid-2022 and secretly distributed decryption keys to over 300 victims, preventing more than USD 130 million in ransom demands.
Threat Actor
RaaS operators with affiliates worldwide.
Technical Indicators
Encryption Extension
.hive
Encryption Algorithm
Custom curve25519-xsalsa20 (Go); later versions written in Rust
Ransom Note Name
HOW_TO_DECRYPT.txt
Targeted Industries
Healthcare, Education, Government, Critical infrastructure
First Seen
June 2021
Last Seen
January 2023 (FBI takedown)
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |