Ransomware Group intelligence
Hive
InactiveTrack Hive with 209 published victims and 3 known leak locations in a single intelligence view.
Overview
Hive is tracked by Breach House as a ransomware group with 209 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 2h ago | hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | hiveapi4nyabjdfz2hxdsr7otrcv6zq6m4rk5i2w7j64lrtny4b7vjad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion |
Top Activity Sectors (16)
- Not identified 111
- Services 20
- Healthcare / Pharma 13
- Education 12
- Communication / Marketing 10
- Manufacturing / Engineering 8
- IT 7
- Public Sector 6
- Finance / Legal / Insurance 5
- Energy 4
- Telecommunications 3
- Transportation / Travel / Logistics 3
- Construction / Real Estate 2
- Agriculture / Food 2
- Hospitality / Food & Beverage / Tourism 1
- NGOs / Associations 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Hive, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: hive uses PowerShell scripts to execute malicious commands and deploy payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: hive disables security tools like antivirus software and monitoring agents to evade detection during attacks.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: hive deletes Volume Shadow Copies and backup directories to prevent data recovery and increase pressure.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: hive queries system network connections to map active services and identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1120 Peripheral Device Discovery Discovery
What they do: hive discovers peripheral devices to locate sensitive data requiring encryption before ransomware deployment.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1135 Network Share Discovery Discovery
What they do: hive performs network share discovery to identify accessible SMB shares for lateral movement and victim data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: hive leverages SMB/Windows Admin Shares for lateral movement across networked hosts within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: hive exfiltrates stolen victim data via encrypted C2 channels to enable double extortion tactics.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: hive encrypts victim files using strong symmetric cryptography to maximize impact and ransom demand.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: hive invokes system recovery inhibition commands to prevent automated backups or remediation processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (22)
▼Software Hive has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1q4frmv39nmvdsxjnen8jm7ykgz68w7p38v5pry9 |
bitcoin | $584,731 | 2 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HOW_TO_DECRYPT.txt
Your network has been breached and all data were encrypted.
Personal data, financial reports and important documents are ready to disclose.
To decrypt all the data and to prevent exfiltrated files to be disclosed at
http://hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion/
you will need to purchase our decryption software.
Please contact our sales department at:
http://hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion/
Login: [snip]
Password: [snip]
To get an access to .onion websites download and install Tor Browser at:
https://www.torproject.org/ (Tor Browser is not related to us)
Follow the guidelines below to avoid losing your data:
- Do not delete or reinstall VMs. There will be nothing to decrypt.
- Do not modify, rename or delete *.key files. Your data will be
undecryptable.
- Do not modify or rename encrypted files. You will lose them.
- Do not report to the Police, FBI, etc. They don't care about your business.
They simply won't allow you to pay. As a result you will lose everything.
- Do not hire a recovery company. They can't decrypt without the key.
They also don't care about your business. They believe that they are
good negotiators, but it is not. They usually fail. So speak for yourself.
- Do not reject to purchase. Exfiltrated files will be publicly disclosed.
hive.txt
Your network has been breached and all data were encrypted.
Personal data, financial reports and important documents are ready to disclose.
To decrypt all the data and to prevent exfiltrated files to be disclosed at
http://hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion/
you will need to purchase our decryption software.
Please contact our sales department at:
http://hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion/
Login: [snip]
Password: [snip]
To get an access to .onion websites download and install Tor Browser at:
https://www.torproject.org/ (Tor Browser is not related to us)
Follow the guidelines below to avoid losing your data:
- Do not modify, rename or delete *.key.rrumj files. Your data will be
undecryptable.
- Do not modify or rename encrypted files. You will lose them.
- Do not report to the Police, FBI, etc. They don't care about your business.
They simply won't allow you to pay. As a result you will lose everything.
- Do not hire a recovery company. They can't decrypt without the key.
They also don't care about your business. They believe that they are
good negotiators, but it is not. They usually fail. So speak for yourself.
- Do not reject to purchase. Exfiltrated files will be publicly disclosed.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (209)
Search, filter and paginate the victim timeline for Hive. Showing 101–200 of 209.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | CARTEGRAPH id3481 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Tri-Ko id3477 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Faw-Volkswagen Automobile Co., Ltd. id3367 View details | China | Telecommunications | — | |
|
No additional victim description available. |
|||||
| Ransomware | Monterey Mechanical Co. id3321 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Attica Group id3297 View details | Greece | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | SSK Ingeniería Y Construcción S.A.C. id3277 View details | Peru | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | MILLS GROUP id3195 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FCCH id3106 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PHC id3010 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Konradin Mediengruppe GmbH id2970 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pollmann id2966 View details | Austria | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Passero Associates id2962 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | KONECTA SERVICIOS ADMINISTRATIVOS Y TECNOLOGICOS S.L. SUCURSAL ARGENTINA id2956 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Banco Caribe id2948 View details | Dominican Republic | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | Asphalion id2947 View details | Spain | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Instituto De Gesto Estratégica De Sade Do Distrito Federal id2941 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Wibag Bau Ag id2940 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Otto Dörner GmbH & Co. KG id2927 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | GomeA id2926 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ministry For Foreign Affairs Of The Republic Of Indonesia id2925 View details | Indonesia | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | UCSI University id2924 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | School District Of Janesville id2923 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rotoplas id2922 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Centurion Stone id2921 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Dayton T. Brown, Inc id2920 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Centerline Communication Llc id2919 View details | United States | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Polynt Group id2915 View details | Italy | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | NSM Insurance Group id2884 View details | United States | Finance / Legal / Insurance | — | |
|
No additional victim description available. |
|||||
| Ransomware | PAN AMERICAN ENERGY S.L. SUCURSAL ARGENTINA id2773 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Steven L. Sugarman & Associates id2723 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Palacios & Asociados id2722 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sit'N Sleep id2721 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MAS & Coronis Health id2720 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | BERMAN SOBIN GROSS & DARBY id2719 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rocky's Ace Hardware id2718 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Guts Superpols Co., Ltd. id2717 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ningbo Dechang Electric Machinery Manufacturing Co., Ltd. id2716 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Tite - Live Belgique id2715 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Shanghai Huizhong Automotive Manufacturing Co., Ltd. id2714 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Supernus Pharmaceuticals, NASDAQ: SUPN id2713 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Drake & Scull International PJSC id2712 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Institute For Systems And Robotics (Isr-Lisboa id2711 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Centre D'Odontologia Integrada Miret-Puig id2710 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hyundai Samho Heavy Industries Co.,Ltd. (South Korea) id2709 View details | Korea, Republic of | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Rodonaves Transportes E Encomendas Ltda id2708 View details | Brazil | Transportation / Travel / Logistics | — | |
|
No additional victim description available. |
|||||
| Ransomware | Eurocoin Interactive B.V. id2707 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Emil Frey id2706 View details | Switzerland | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Friedrich id2705 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Powerhouse1 id2704 View details | United States | Energy | — | |
|
No additional victim description available. |
|||||
| Ransomware | Doner id2703 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | EBM id2702 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ITS InfoCom id2701 View details | Costa Rica | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Vermeer Southeast id2510 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Unita Locale Socio id2509 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The British Columbia Institute Of Technology id2508 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sutterfield Financial Group id2507 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Schuldnerberatung Ostfriesland e. V. id2506 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sardinha Family Trust id2505 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sadbhav Engineering Limited id2504 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ryan Companies id2503 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Résidence Les Chtaigniers id2502 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Powell Transportation id2501 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Northern Financial Services id2500 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Montour School District id2499 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mele Printing id2498 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Marten Transport id2497 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Macquarie Health Corporation id2496 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Johnson Memorial Health id2495 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Haselden Construction id2494 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Greenway Health id2493 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Florida Sugar Cane League id2492 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Family Christian Health Center id2491 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Erik Buell Racing id2490 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Creative Liquid Coatings INC id2489 View details | United States | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | ConForm Automotive id2488 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Claro Colombia id2487 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Brinkman Turkey Farms id2486 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Brakke Asbestsanering BV id2485 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bohlke International Airways id2484 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Advanced Geosciences id2483 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ANTHONY CATALFANO INTERIORS id2482 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | UNICRED id2471 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | RIVADIS id2470 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ezz Steel id2416 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Metro.Us id2304 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | WOLSEY id2248 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Madix Inc id2247 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Altus Group id2221 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mega Vision id2220 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | HI FLY id2219 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | IBC24 News id2218 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SS Design id2217 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GURTEEN id2216 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Net Ninjas id2215 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | W.H. Stovall id2214 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ospray Video id2213 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GK.NO id2212 View details | Norway | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | KBM UK id2211 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | EMCO id2210 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Aria Systems id2209 View details | Services | — | ||
|
No additional victim description available. |
|||||