Hive

Inactive
Hive is a strain of ransomware that was first discovered in June 2021. Hive was designed to be used by Ransomware-as-a-service providers, to enable novice cyber-criminals to launch ransomware attacks on healthcare providers, energy providers, charities, and retailers across the globe. In 2022 there was a switch from GoLang to Rust.
208 Victims
Aug 13, 2021 First Discovered
Jan 16, 2023 Last Discovered
1339 Days Inactive
0% Infostealer
0/3 Sites Online
Known Locations (3)
This domain has been seized
hiveapi4nyabjdfz2hxdsr7otrcv6zq6m4rk5i2w7j64lrtny4b7vjad.onion
This domain has been seized
hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion
This domain has been seized
hivecust6vhekztbqgdnkks64ucehqacge3dij3gyrrpdp57zoq3ooqd.onion
Tools Used
DefenseEvasion
GMER, PCHunter
DiscoveryEnum
Advanced IP Scanner, Bloodhound, SoftPerfect NetScan
Exfiltration
MEGA, PrivatLab, RClone, Sendspace, UFile
LOLBAS
BCDEdit, BITSAdmin, WMIC, Windows Event Utility (wevtutil)
Offsec
Cobalt Strike, Impacket, Metasploit, Meterpreter, PowerShell Empire
RMM-Tools
Atera, ScreenConnect, Splashtop
Intelligence
Victims (208)

Detailed victim list temporarily unavailable

This group has 208 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.