Uptime Hamster: 11d 11h 50mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Hive0117

Hive0117

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
Hive0117 is a financially motivated cybercriminal group that emerged in February 2022, primarily conducting phishing campaigns. This group is distinct from the Hive ransomware group. Hive0117's operations are characterized by their consistent use of the fileless DarkWatchman malware and their strategy of imitating official government communications, particularly leveraging current political and social events such as military conscription notices to create urgency and trick victims. The group's origin remains unclear, though their targeting often focuses on Eastern European entities. A defining characteristic is the DarkWatchman malware's ability to query for smartcard readers, suggesting a focus on higher security targets, combined with its fileless nature and mechanisms to erase traces of its presence.
Tecnicas MITRE
T1566 - Phishing
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
21
Actualizado
Sat, 17 Ma