Hive0117
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
Hive0117 is a financially motivated cybercriminal group that emerged in February 2022, primarily conducting phishing campaigns. This group is distinct from the Hive ransomware group. Hive0117's operations are characterized by their consistent use of the fileless DarkWatchman malware and their strategy of imitating official government communications, particularly leveraging current political and social events such as military conscription notices to create urgency and trick victims. The group's origin remains unclear, though their targeting often focuses on Eastern European entities. A defining characteristic is the DarkWatchman malware's ability to query for smartcard readers, suggesting a focus on higher security targets, combined with its fileless nature and mechanisms to erase traces of its presence.