Hive — Ransomware Profile
Hive ransomware primarily targeted healthcare organizations before the FBI secretly infiltrated the operation in 2022, providing victims with decryption keys.Also tracked as
Hive Ransomware
IntelFusions coverage (3)
- Hackers' AI chatbot server exposed Latin American attacks 2026-09-03 · AI Security
- Hackers turn hacked SQL servers into mining rigs and VPN relays 2026-07-29 · Cyber Incidents
- CISA #StopRansomware: Hive Ransomware Claims 1,300+ Victims and $100M in Payments Targeting Healthcare and Critical Infrastructure 2026-02-16 · Ransomware
Tools & malware
- Cobalt Strike Post-exploitation framework
- Hive (encryptor) Ransomware
- Impacket Post-exploitation toolkit
- MEGA Exfiltration / cloud storage
- Metasploit Post-exploitation framework
- Mimikatz Credential dumper
- Rclone Exfiltration tool
- ScreenConnect Remote access (RMM)
- Splashtop Remote access (RMM)
Vendor research
- #StopRansomware: Hive Ransomware (AA22-321A) CISA / FBI / HHS
- Hive ransomware gets upgrades in Rust Microsoft
- Inside the Hive Group-IB
- Hive Ransomware Analysis Varonis
- New Hunters International ransomware possible rebrand of Hive BleepingComputer
Countries linked to this actor
- Costa Rica targets