HIVE-0145
0 incidentes
0 paises
0 sectores
apt Unknown Ultimo: -
HIVE-0145, also known as Hive0145, is a cybercriminal initial access broker (IAB) tracked by IBM X-Force. The group emerged in late 2022 and has since evolved its operations from generic phishing to advanced attachment hijacking. Its primary motivation is financial gain, specializing in stealing email credentials to sell access or enable further attacks, such as business email compromise (BEC). What sets this group apart is its exclusive and frequent use of Strela Stealer, likely operated solely by this actor, coupled with a distinct tactical evolution involving the weaponization of stolen legitimate emails and real invoices for phishing authenticity. There is no public attribution of HIVE-0145 to a specific country; it is understood to operate within the broader cybercriminal ecosystem.