• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Hive Ransomware Has Made $100m to Date

You are here: Home / General Cyber Security News / Hive Ransomware Has Made $100m to Date
November 18, 2022

The Hive ransomware variant has manufactured its operators and affiliate marketers about $100 million so far from around 1300 worldwide firms, in accordance to a new inform.

The joint advisory was introduced yesterday by the FBI, the US Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Wellness and Human Products and services (HHS).

The believed revenue produced by the ransomware-as-a-support (RaaS) variant arrive in excess of a time period of all over 15 months, after it was initially uncovered back in June 2021.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Sufferer businesses have appear from a broad assortment of verticals together with governing administration, communications, critical production and IT, whilst the team apparently has a particular emphasis on health care.

In the previous, the group’s affiliates gained initial entry to sufferer networks via phishing email messages that contains booby-trapped attachments that exploited Microsoft Exchange Server vulnerabilities.

They’ve also targeted on distant desktop infrastructure.

“Hive actors have obtained preliminary access to target networks by employing one-factor logins by means of Distant Desktop Protocol (RDP), digital private networks (VPNs) and other remote network connection protocols,” the inform defined.

“In some circumstances, Hive actors have bypassed multifactor authentication (MFA) and attained entry to FortiOS servers by exploiting CVE-2020-12812. This vulnerability enables a destructive cyber-actor to log in devoid of a prompt for the user’s second authentication factor (FortiToken) when the actor variations the situation of the username.”

Publish-intrusion action contains terminating backup and antivirus (AV) processes, getting rid of shadow duplicate products and services and deleting Windows celebration logs together with System, Security and Application logs.

The team also disables Windows Defender and other popular AV packages in the process registry prior to exfiltrating and encrypting facts.

The alert warned that Hive actors have been regarded to reinfect target networks if businesses restored from backups with no creating a ransom payment.


Some pieces of this post are sourced from:
www.infosecurity-journal.com

Previous Post: «hive ransomware attackers extorted $100 million from over 1,300 companies Hive Ransomware Attackers Extorted $100 Million from Over 1,300 Companies Worldwide
Next Post: Netflix Phishing Emails Surge 78% Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.