Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors HIVE-0145

Also known as: Hive0145, tracked as, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, U2DiskWatch, control module

Description

Hive-0145, also known as Hive0145 or Project Spy, operates primarily for financial gain through credential theft and phishing. Since late 2022 the group has evolved from generic spear‑phishing campaigns to sophisticated, automated operations that reuse compromised legitimate email accounts adorned with seemingly innocuous invoice attachments. The core payload, Strela Stealer, is designed to intercept and exfiltrate credentials from Outlook and Thunderbird clients, while also collecting local configuration data. Beyond credential harvesting, Hive-0145 bundles a modular back‑door infrastructure comprising tools such as NoFive/PUBLOAD, Plat1/T9000, and occasionally Cobalt Strike. These components provide persistence, remote execution capabilities, and covert command‑and‑control channels—often tunneled over DNS or other application‑layer protocols—to orchestrate post‑exploitation actions. The group’s operations show increasing automation, which allows rapid scaling of phishing vectors and the deployment of additional payloads across multiple victim machines. Analysis of the actor’s campaigns reveals a focus on sectors that hold valuable data and financial assets: finance, government, defense, telecommunications, energy, healthcare, and critical infrastructure. Attackers leverage domain registration practices typical of bullet‑proof hosting providers, staging malware in user directories or publicly writable locations, thereby obfuscating initial compromise activity.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Telecommunications
Manufacturing
Energy
Healthcare
Education
Transportation
Critical infrastructure
Media
Retail
Information technology
Aerospace
Mining
Pharmaceutical
Aviation
Maritime
Chemical
Legal services
Nuclear
Hospitality
Gaming

Targeted Countries / Regions

US
DE
UA
ES
RU
GB
BR
KR
CN
PL
IN
AU
MX
CA
JP
IL
TR
SY
TW
IT
SA
IR
FR
VN
SG
AE
NL
AZ
KZ

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Hive-0145 is a financially motivated initial‑access broker that has been active since late 2022, leveraging the Strela Stealer malware to harvest email credentials from Microsoft Outlook and Mozilla Thunderbird. Their phishing campaigns increasingly use stolen legitimate email accounts attached with invoice documents, targeting high‑value sectors across Europe and beyond. The group may also deploy backdoors such as Cobalt Strike, NoFive, and Plat1/T9000 to facilitate persistence, lateral movement, and data exfiltration.

Goals & Targeting

Hive-0145’s strategic objectives revolve around monetary exploitation. By stealing email credentials they can infiltrate internal networks, conduct fraudulent transactions, and sell access to third parties. The group targets sectors with high financial value or sensitive personal data—such as banking, government, defense, telecoms, healthcare, and energy—to maximize the potential payoff from compromised identities. Geographically, their focus on EU countries (Spain, Germany, Ukraine) reflects both the prevalence of vulnerable security practices and high-value corporate objectives in these markets.

Enhanced Description

Key Capabilities

  • Spear‑phishing with legitimate email accounts and invoice attachments
  • Credential harvesting via Strela Stealer from Outlook and Thunderbird
  • Use of custom back‑door frameworks (NoFive/PUBLOAD, Plat1/T9000) for persistence and lateral movement
  • Remote access capabilities with Cobalt Strike to orchestrate post‑exploitation actions
  • Automated campaign orchestration at scale

ATT&CK Techniques

Command & Control
1 technique
Discovery
1 technique
Stealth
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Project Spy

Intel Summary

5

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

4

Tactics

Tags

APT
Critical Infrastructure
Phishing
Data Exfiltration
Financial TTPs
Cybercrime
Email theft
Spain
Germany
Ukraine

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.