Home/Threat Actor/Hive
Threat Actor

Hive

hive_ransomware · russia_speaking_cybercrime · active since 2021

Hive (HiveLeaks / Hive Operators / G1051) was one of the most operationally consequential ransomware operations of the 2021- 2023 period, a financially-motivated organized cyber-criminal cluster operating from Russia and adjacent post-Soviet states from June 2021 through January 2023 (approximately nineteen months of sustained operations), with documented compromise of more than 1,500 organizations globally and estimated ransom collection exceeding $100M USD across the operational lifespan per CISA + FBI + HHS joint cybersecurity advisory AA22-321A (November 17, 2022)

strongest formal-attribution profile of any 2021-2023 ransomware operation grounded in the seminal FBI Operation Hive Killer (announced January 26, 2023), one of the most operationally consequential counter-ransomware operations in the publicly-tracked record and one of the most operationally significant covert counter-cybercrime operations of any kind, featuring sustained 7-month FBI covert infiltration of Hive operational infrastructure from approximately July 2022 through January 2023 during which FBI captured ~1,300 decryption keys and distributed them to ~336 Hive victim organizations globally via parallel victim-engagement workflows, preventing ~$130M USD in ransom payments without alerting Hive administrators, followed by coordinated international public takedown with Europol + German Federal Criminal Police Office (BKA) + Netherlands National High Tech Crime Unit including seizure of HiveLeaks leak site and Hive negotiation infrastructure.

covert- operation model operationally innovative and subsequently informed law-enforcement counter-ransomware doctrine partially replicated in Operation Cookie Monster (ALPHV / BlackCat, December 2023) and Operation Cronos (LockBit, February 2024); most operationally consequential single operations the May 2022 Costa Rica CCSS attack disrupting Costa Rica national healthcare IT operations for weeks (alongside contemporaneous Conti government-ministry attack collectively representing one of the most consequential national-government-targeting periods in the publicly-tracked ransomware record) and sustained US healthcare sector targeting across 2021-2023.

cluster operated Go-language ransomware (Hive's original implementation), Linux + ESXi variants, and subsequently Rust-language variant from mid-2022 (one of the earlier Rust-language ransomware operations alongside ALPHV / BlackCat).

russia_speaking_cybercrime confidence: high 16 aliases

Profile

Hive (also tracked as HiveLeaks, Hive Operators, and MITRE ATT&CK G1051) was one of the most operationally consequential ransomware operations of the 2021-2023 period, a financially-motivated organized cyber-criminal cluster operating from Russia and adjacent post-Soviet states from June 2021 through January 2023 (approximately nineteen months of sustained operations). The cluster compromised more than 1,500 organizations globally and collected estimated ransoms exceeding $100 million US dollars across the operational lifespan per CISA + FBI + HHS joint cybersecurity advisory AA22-321A (November 17, 2022). The cluster has the strongest formal-attribution profile of any 2021-2023 ransomware operation grounded in the seminal FBI Operation Hive Killer (announced January 26, 2023), one of the most operationally consequential counter-ransomware operations in the publicly-tracked record and one of the most operationally significant covert counter-cybercrime operations of any kind in the publicly-tracked record.

The operation's signature operational model was sustained covert infiltration: FBI infiltrated Hive operational infrastructure in approximately July 2022 and operated covertly inside Hive infrastructure for approximately seven months through January 2023.

During the covert period, the FBI
  • Obtained approximately 1,300 decryption keys from Hive infrastructure.
  • Distributed those keys to approximately 336 Hive victim organizations globally via parallel victim-engagement workflows, preventing approximately $130 million USD in ransom payments without alerting Hive administrators.
  • Maintained operational secrecy throughout the seven-month covert period.
  • Coordinated with international law-enforcement partners including Europol, German Federal Criminal Police Office, and Netherlands National High Tech Crime Unit The covert-operation model was operationally innovative, decryption-key-distribution to victims was conducted throughout the covert period rather than waiting for public takedown, maximizing victim-impact-reduction while preserving the operational secrecy required for sustained intelligence collection. The operation model has subsequently informed law-enforcement counter-ransomware doctrine and was partially replicated in Operation Cronos (LockBit, February 2024) and Operation Cookie Monster (ALPHV / BlackCat, December 2023). Operation Hive Killer's public announcement on January 26, 2023 effectively terminated Hive operations under the Hive brand identity.
The announcement documented
  • Seven months of covert FBI infiltration of Hive infrastructure.
  • Capture of approximately 1,300 decryption keys.
  • Distribution of keys to approximately 336 Hive victim organizations globally.
  • Prevention of approximately $130 million USD in ransom payments.
  • Seizure of Hive operational infrastructure including the HiveLeaks leak site and Hive negotiation infrastructure.
  • Coordinated international announcement with Europol, BKA, and Netherlands National High Tech Crime Unit The cluster's most operationally consequential single operations included the May 2022 Costa Rica CCSS attack disrupting Costa Rica national healthcare IT operations across the country for weeks (alongside the contemporaneous Conti government-ministry attack, collectively representing one of the most operationally consequential national-government-targeting periods in the publicly-tracked ransomware record), and sustained US healthcare sector targeting across 2021-2023 (contributing substantially to elevated US federal-government attention to healthcare-sector ransomware as patient-safety issue). Operationally the cluster operated Go-language ransomware (Hive's original implementation), Linux + ESXi variants, and subsequently introduced a Rust-language variant in mid-2022 (one of the earlier Rust-language ransomware operations alongside ALPHV / BlackCat). The cluster operated as ransomware- as-a-service with affiliate recruitment, central administration of leak-site publication and ransom negotiation, and standard double-extortion tradecraft. Following the January 2023 Operation Hive Killer public takedown, Hive personnel are widely assessed to have subsequently surfaced under new brand identities. The post-Hive personnel diaspora is operationally consistent with the broader Russia-speaking organized cybercrime ecosystem successor-diaspora pattern. A handful of operational notes: First, the cluster represents one of the most operationally significant pre-Operation-Cronos counter-ransomware case studies in the publicly-tracked record. Operation Hive Killer demonstrated that sustained covert law-enforcement operations against ransomware operations can produce substantial operational-impact- reduction (the $130M USD ransom-payment prevention through decryption key distribution represents one of the largest victim-impact-reduction outcomes in the publicly-tracked counter-ransomware record) and can be executed without alerting cluster administrators during sustained covert infiltration periods. The operation provides important operational data points for ongoing counter-ransomware policy and operations. Second, the covert-operation model has subsequently informed law-enforcement counter-ransomware doctrine. The pattern of sustained covert infiltration followed by coordinated international public takedown with operational results disclosure has been partially replicated in Operation Cookie Monster (ALPHV / BlackCat, December 2023) and Operation Cronos (LockBit, February 2024). The model represents one of the more operationally successful counter-ransomware doctrine patterns of the 2022-2024 period. Third, no formal individual-operator attribution at the named- Russian-national tier has been publicly issued for Hive administrators despite the substantial operational impact and the operationally-consequential Operation Hive Killer disruption , consistent with the broader pattern of absence of similar named-individual-attribution for Cl0p, ALPHV / BlackCat, Black Basta, Akira, Play, Medusa, Rhysida, Royal / BlackSuit, RansomHub, Qilin, and several other contemporary cybercrime clusters. Only LockBit (Khoroshev), Evil Corp (Yakubets / Turashev), and FIN7 (Dunaev / Hladyr / Kolpakov / Witte) have received named- Russian-national-tier formal attribution among the major contemporary cybercrime clusters covered in this corpus. Fourth, the cluster's healthcare-sector targeting emphasis across 2021-2023 contributed substantially to elevated US federal-government attention to healthcare-sector ransomware as patient-safety issue. The healthcare-sector targeting pattern observable across Hive, Conti (Ireland HSE May 2021), Black Basta (Ascension Health May 2024), Rhysida (Prospect Medical August 2023 and Lurie Children's January-February 2024), and Qilin (Synnovis UK NHS June 2024) collectively represents sustained contemporary cybercrime operational impact on Western healthcare-sector infrastructure that has fundamentally elevated healthcare-sector cybersecurity as a federal policy priority across Western jurisdictions.

Aliases

16
hivehive ransomwarehive_ransomwarehiveransomwarehive ganghive_ganghive operatorshive_operatorshiveleakshive leakshive_leakshiveleaks sitehiveleaks_siteg1051atk 248atk248

Notable Campaigns

7
2023-2025Post-Hive Personnel Diaspora (January 2023 onward)
2023FBI Operation Hive Killer Public Announcement (January 26, 2023)
2022-2023FBI Covert Infiltration of Hive Infrastructure (July 2022 - January 2023)
2022CISA + FBI + HHS AA22-321A Hive Cybersecurity Advisory (November 17, 2022)
2022Costa Rica CCSS (Caja Costarricense de Seguro Social) Attack (May 2022)
2021-2023Sustained US Healthcare Sector Targeting (2021-2023)
2021Hive Emergence (June 2021)

Attribution & Reporting

Attributed by
FBI Cyber DivisionCISA (US Cybersecurity and Infrastructure Security Agency)HHS Health Sector Cybersecurity Coordination Center (HC3)US Department of JusticeEuropol European Cybercrime Centre (EC3)German Federal Criminal Police Office (BKA)Netherlands National High Tech Crime UnitMandiant / Google Cloud Threat IntelligenceMicrosoft Threat Intelligence CenterCrowdStrikeRecorded Future Insikt GroupSentinelOneSophosTrend MicroKaspersky GReATGroup-IBPRODAFTCovewareHalcyonCybereasonIBM X-ForceTrustwave SpiderLabsPalo Alto Networks Unit 42Symantec (Broadcom)TrellixDFIR Report
Key reporting
reportCISA + FBI + HHS: AA22-321A #StopRansomware Hive Joint Cybersecurity Advisory (November 17, 2022), first major US-government formal public attribution documenting 1500+ orgs and $100M+ USD collected ransoms
reportUS DOJ: US Department of Justice Disrupts Hive Ransomware Variant (January 26, 2023), Operation Hive Killer announcement
reportFBI: FBI Announces Seizure of Hive Ransomware Infrastructure (January 26, 2023)
reportEuropol: Cybercriminals Stung as Hive Infrastructure Shut Down (January 26, 2023), coordinated international announcement
reportCrowdStrike: Hive Ransomware Deep Dive (multiple years)
reportMandiant: Hive Ransomware Continued Tracking
reportMicrosoft Threat Intelligence: Hive Ransomware Rust Variant (July 2022)
reportCisco Talos: Hive Ransomware Deep Dive
reportPalo Alto Networks Unit 42: Hive Ransomware Operational Analysis
reportTrend Micro: Ransomware Spotlight Hive
reportSophos: Hive Ransomware (February 2022)
reportSentinelOne Labs: Hive Ransomware Tracking
reportRecorded Future Insikt Group: Hive Ransomware Tracking
reportCoveware: Hive Ransomware Affiliate Tracking
reportHalcyon: Hive Operational Profile
reportPRODAFT: Hive Detailed Operational Analysis
reportGroup-IB: Hive Continued Tracking
reportTrustwave SpiderLabs: Hive Tracking
reportTrellix: Hive Operational Analysis
reportSymantec (Broadcom): Hive Ransomware Tracking
reportDFIR Report: Hive Operational Analysis
reportIBM X-Force: Hive Continued Tracking
reportMalpedia Actor Profile: Hive
reportMITRE ATT&CK Group G1051, Hive

Operational

State sponsor

Hive is a financially-motivated organized cyber-criminal cluster , not a state-aligned cluster, operating predominantly from Russia and adjacent post-Soviet states. The cluster operated from June 2021 through January 2023, approximately nineteen months of sustained operations terminated by one of the most operationally significant counter-ransomware operations in the publicly-tracked record. The cluster has the strongest formal- attribution profile of any 2021-2023 ransomware operation grounded in the seminal FBI Operation Hive Killer (announced January 26, 2023), a 7-month covert FBI operation that infiltrated Hive operational infrastructure in approximately July 2022 and operated covertly inside Hive infrastructure through January 2023 before the public takedown announcement.

Operation Hive Killer represented one of the most operationally consequential counter-ransomware operations of the pre-Operation- Cronos era and established important operational doctrine patterns subsequently replicated in Operation Cronos (LockBit, February 2024) and Operation Cookie Monster (ALPHV / BlackCat, December 2023). Operation Hive Killer accomplished documented operational results: capture of approximately 1,300 decryption keys subsequently distributed to approximately 336 Hive victim organizations globally, prevention of approximately $130 million US dollars in ransom payments (representing the substantial victim ransom-payment-pressure reduction enabled by the decryption key distribution), seizure of Hive operational infrastructure including the Hive leak site and Hive negotiation infrastructure, and substantial public-attribution disclosure of internal Hive operational details obtained from seized infrastructure. The cluster's earlier CISA + FBI + HHS joint cybersecurity advisory AA22-321A (November 17, 2022) documented Hive responsibility for compromise of more than 1,500 organizations globally and estimated ransom collection exceeding $100 million US dollars across the operational lifespan.

No formal individual-operator attribution at the named-Russian- national tier has been publicly issued for Hive administrators despite the substantial operational impact and the operationally- consequential Operation Hive Killer disruption, a notable analytical gap consistent with the absence of similar named- individual-attribution for Cl0p, ALPHV / BlackCat, Black Basta, and several other contemporary cybercrime clusters.

Motivations
financial_gain, financially_motivated, cybercrime, ransomware_deployment, extortion, double_extortion, ransomware_as_a_service_operations, healthcare_sector_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA NZMETERPRETERMSHTASHARPHOUNDSPLASHTOP ABUSE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin