Hive
Aliases: Hive ransomware
Source profile review date: 2026-06-01
Added to the source registry: 2021-08-14 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
Locally generated translation; linguistic review is still pending.
Executive summary
Hive was a large RaaS operation with broad sector impact, known for phishing, RDP/VPN, credential theft, log removal, data steal and double extortion.
Hive is historically important because FBI, CISA and HHS linked the group to more than a thousand victims and an adult RaaS chain. The profile remains usable as a defense model for phishing, remote access, credential theft, data exfiltration and repair disruption.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Management summary
Hive is no longer a new name in the same form, but remains an important actor profile because the process comes back to modern ransomware operations. FBI, CISA and HHS published a StopRansomware advisory linking Hive to wide global impact, double extortion and use of various TTP cyclists. For visitors, Hive is especially useful as a blueprint: how is access built up, how is data stolen and how is recovery put under pressure?
Hive attacks often combined phishing, stolen or brute-forced credials, remote access and misuse of legitimate tooling. Then followed privilege building, discovery, data stealing and encryption. This chain is still current with subsequent ransomware brands. An organization that arms against Hive-like patterns, consequently also reduces risk against other groups.
The main administrative message is that ransomware prevention does not start with the encryption device. Hive shows that the damage already occurs in credential theft, insufficient network segmentation, log removal and unattended data exfiltration.
Grouping and development
Hive was described as RaaS operation where affiliates conducted attacks and shared the proceeds. The group used a leak site and double extortion: encryption plus threat with publication. That model has now become standard in ransomware, but Hive was one of the well-known operations that applied it on a large scale.
The advisory mentions that Hive had affected more than 1,300 companies worldwide and received around 100 million dollars in ransom. Such numbers are not only historically relevant; they show why scalable attack paths such as phishing, RDP and VPN are so attractive to affiliates.
Hive was disrupted by international law enforcement at the beginning of 2023, but the methodologies remain relevant. Affiliates, tools and access routes do not automatically disappear when a brand disappears. Therefore, Hive should remain as a historical profile in the database, with emphasis on transferable lessons.
Attack pattern from public cases
Hive actors used multiple initial access routes, including phishing emails with malicious attachments, compromised VPN-credentials and vulnerable remote access. This variation means that defense should be broad: mail security, MFA, patching of edge systems and monitoring for credential abuse.
After access, legitimate tooling and commands for discovery, lateral motion and execution were often used. The advisory mentions that some IOC disregarded applications are legitimate applications by Hive-actors. That's an important point: a tool is not safe because it is known; context determines whether use is normal.
Hive actors removed Windows Event Logs, specifically System, Security and Application logs. This makes central logging essential. An organization that only stores local logs may have lost crucial timeline information after an attack.
Data digs and double extortion were core parts. Search for staggering folders, compression, large outbound transfers and cloud storage usage at Hive-like threats. Encryption is the visible impact, but exfiltration often determines administrative damage.
Known IOCs and artifacts
The Hive advisory contains IOC- tables of tools and indicators used during compromise. As part of this includes legitimate software, validation should always be done on host, account, time, command line and network destination.
Windows Event Log clearing is a concrete behavior signal. Clearing of System, Security and Application logs after remote login or privilege usage must be investigated immediately.
Double extortion also produces non-technical artifacts: ransom notes, leak site entries, negotiation contact and claims about stolen data. These signals are valuable but must be linked to technical traces before scope is established.
Victim pattern and lessons
Hive, according to public sources, has affected organisations worldwide and across multiple sectors. The scale shows that affiliates are mainly looking for organizations with useful access, valuable data and insufficient segmentation.
The main lesson is that security maturity can be unevenly distributed. An organization may have good endpoint security but weak VPN, or good backups but no view of exfiltration. Hive-like attacks exploit precisely those gaps between teams.
Because Hive has been historically disturbed, the profile should not be read as a current claim machine but as a case study. The attack chain remains defensiblely relevant to modern RaaS operations.
How to arm yourself against Hive
Combine phishing reversibility with technical checks: attachment-sandboxing, DMARC/SPF/DKIM, awareness, but especially MFA and condition access so that a stolen password is not enough.
Set central logging for Windows Event Logs, VPN, EDR, firewall and identity. Local log removal must not break the reconstruction.
Limit lateral movement with network segmentation, least privilege and management via jump hosts. Check that service accounts have no unnecessary domain-wide rights.
Make exfiltration visible. Monitor large compression files, staging directories, unusual cloud tools and outbound volume to unknown destinations.
Test recovery under realistic conditions: domain compromise, discontinued security services and partially lost servers. Hive-like attacks not only touch files but also trust in management and recovery.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| behavior | clearing System, Security and Application Windows Event Logs | CISA AA22-321A | Hive actors delete Windows event logs. |
| access | phishing attachments / compromised VPN credentials | CISA AA22-321A | Observed initial access categories. |
| behavior | double extortion with leak-site pressure | CISA AA22-321A | Hive used encryption and threatened publication of exfiltrated data. |
| tooling | legitimate applications used during compromise | CISA AA22-321A | CISA notes some indicators are legitimate apps misused by Hive actors. |
Sources
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.