Hive Ransomware

Description Summary

Hive was a major ransomware-as-a-service active from June 2021 until its infrastructure was disrupted by a coordinated FBI/Europol operation in January 2023. The FBI had infiltrated Hive's network in mid-2022 and secretly distributed decryption keys to over 300 victims, preventing more than USD 130 million in ransom demands.

Threat Actor

RaaS operators with affiliates worldwide.

Technical Indicators

Encryption Extension
.hive
Encryption Algorithm
Custom curve25519-xsalsa20 (Go); later versions written in Rust
Ransom Note Name
HOW_TO_DECRYPT.txt
Targeted Industries
Healthcare, Education, Government, Critical infrastructure
First Seen
June 2021
Last Seen
January 2023 (FBI takedown)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop