Ransomware Group intelligence
Hive
InactiveTrack Hive with 209 published victims and 3 known leak locations in a single intelligence view.
Overview
Hive is tracked by Breach House as a ransomware group with 209 published victims.
United States is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 2h ago | hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | hiveapi4nyabjdfz2hxdsr7otrcv6zq6m4rk5i2w7j64lrtny4b7vjad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion |
Top Activity Sectors (16)
- Not identified 111
- Services 20
- Healthcare / Pharma 13
- Education 12
- Communication / Marketing 10
- Manufacturing / Engineering 8
- IT 7
- Public Sector 6
- Finance / Legal / Insurance 5
- Energy 4
- Telecommunications 3
- Transportation / Travel / Logistics 3
- Construction / Real Estate 2
- Agriculture / Food 2
- Hospitality / Food & Beverage / Tourism 1
- NGOs / Associations 1
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Hive, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: hive uses PowerShell scripts to execute malicious commands and deploy payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: hive disables security tools like antivirus software and monitoring agents to evade detection during attacks.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: hive deletes Volume Shadow Copies and backup directories to prevent data recovery and increase pressure.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1049 System Network Connections Discovery Discovery
What they do: hive queries system network connections to map active services and identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1120 Peripheral Device Discovery Discovery
What they do: hive discovers peripheral devices to locate sensitive data requiring encryption before ransomware deployment.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1135 Network Share Discovery Discovery
What they do: hive performs network share discovery to identify accessible SMB shares for lateral movement and victim data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: hive leverages SMB/Windows Admin Shares for lateral movement across networked hosts within victim environments.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: hive exfiltrates stolen victim data via encrypted C2 channels to enable double extortion tactics.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: hive encrypts victim files using strong symmetric cryptography to maximize impact and ransom demand.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: hive invokes system recovery inhibition commands to prevent automated backups or remediation processes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (22)
▼Software Hive has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (1)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1q4frmv39nmvdsxjnen8jm7ykgz68w7p38v5pry9 |
bitcoin | $584,731 | 2 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
HOW_TO_DECRYPT.txt
Your network has been breached and all data were encrypted.
Personal data, financial reports and important documents are ready to disclose.
To decrypt all the data and to prevent exfiltrated files to be disclosed at
http://hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion/
you will need to purchase our decryption software.
Please contact our sales department at:
http://hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion/
Login: [snip]
Password: [snip]
To get an access to .onion websites download and install Tor Browser at:
https://www.torproject.org/ (Tor Browser is not related to us)
Follow the guidelines below to avoid losing your data:
- Do not delete or reinstall VMs. There will be nothing to decrypt.
- Do not modify, rename or delete *.key files. Your data will be
undecryptable.
- Do not modify or rename encrypted files. You will lose them.
- Do not report to the Police, FBI, etc. They don't care about your business.
They simply won't allow you to pay. As a result you will lose everything.
- Do not hire a recovery company. They can't decrypt without the key.
They also don't care about your business. They believe that they are
good negotiators, but it is not. They usually fail. So speak for yourself.
- Do not reject to purchase. Exfiltrated files will be publicly disclosed.
hive.txt
Your network has been breached and all data were encrypted.
Personal data, financial reports and important documents are ready to disclose.
To decrypt all the data and to prevent exfiltrated files to be disclosed at
http://hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion/
you will need to purchase our decryption software.
Please contact our sales department at:
http://hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion/
Login: [snip]
Password: [snip]
To get an access to .onion websites download and install Tor Browser at:
https://www.torproject.org/ (Tor Browser is not related to us)
Follow the guidelines below to avoid losing your data:
- Do not modify, rename or delete *.key.rrumj files. Your data will be
undecryptable.
- Do not modify or rename encrypted files. You will lose them.
- Do not report to the Police, FBI, etc. They don't care about your business.
They simply won't allow you to pay. As a result you will lose everything.
- Do not hire a recovery company. They can't decrypt without the key.
They also don't care about your business. They believe that they are
good negotiators, but it is not. They usually fail. So speak for yourself.
- Do not reject to purchase. Exfiltrated files will be publicly disclosed.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (209)
Search, filter and paginate the victim timeline for Hive. Showing 201–209 of 209.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | WAMGROUP id2208 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | XacBank id2207 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | APR Supply id2206 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grupo5 id2205 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | MediaMarkt id2204 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GryphTech id2203 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Raveco id2202 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Missouri Delta Medical Center id678 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Memorial Health System id673 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||