Hive0137
0 incidentes
0 paises
0 sectores
apt Ultimo: -
Hive0137 is a highly active malware distribution threat actor that emerged in October 2023, specializing in large-scale phishing campaigns. The group primarily functions by delivering various loaders and backdoors, which are subsequently used to provide initial access for ransomware affiliates, indicating a clear financial motivation. It is assessed with moderate confidence to be associated with Eastern European cybercrime syndicates, notably through its close relationships with former members of the ITG23 (Conti/Trickbot) group. Hive0137 distinguishes itself by its complex infection chains, which X-Force nominated as among the most intricate in 2023, and its pioneering use of generative AI tools to craft authentic and unique phishing emails and potentially assist in script development. While primarily operating under the Hive0137 designation, its campaigns have shown overlaps with Proofpoint's TA571 cluster, and its distribution methods are sometimes compared to Hive0118 (TA577).
Sectores objetivo (SOCRadar)
Information ServicesOtherOther Information Services