Also known as: Hive0145, tracked as, Project Spy, Cridex, similar to Sliver, Cobalt Strike, consists of multiple components, NoFive, Plat1, U2DiskWatch, control module
Hive-0145, also known as Hive0145 or Project Spy, operates primarily for financial gain through credential theft and phishing. Since late 2022 the group has evolved from generic spear‑phishing campaigns to sophisticated, automated operations that reuse compromised legitimate email accounts adorned with seemingly innocuous invoice attachments. The core payload, Strela Stealer, is designed to intercept and exfiltrate credentials from Outlook and Thunderbird clients, while also collecting local configuration data. Beyond credential harvesting, Hive-0145 bundles a modular back‑door infrastructure comprising tools such as NoFive/PUBLOAD, Plat1/T9000, and occasionally Cobalt Strike. These components provide persistence, remote execution capabilities, and covert command‑and‑control channels—often tunneled over DNS or other application‑layer protocols—to orchestrate post‑exploitation actions. The group’s operations show increasing automation, which allows rapid scaling of phishing vectors and the deployment of additional payloads across multiple victim machines. Analysis of the actor’s campaigns reveals a focus on sectors that hold valuable data and financial assets: finance, government, defense, telecommunications, energy, healthcare, and critical infrastructure. Attackers leverage domain registration practices typical of bullet‑proof hosting providers, staging malware in user directories or publicly writable locations, thereby obfuscating initial compromise activity.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Hive-0145 is a financially motivated initial‑access broker that has been active since late 2022, leveraging the Strela Stealer malware to harvest email credentials from Microsoft Outlook and Mozilla Thunderbird. Their phishing campaigns increasingly use stolen legitimate email accounts attached with invoice documents, targeting high‑value sectors across Europe and beyond. The group may also deploy backdoors such as Cobalt Strike, NoFive, and Plat1/T9000 to facilitate persistence, lateral movement, and data exfiltration.
Goals & Targeting
Hive-0145’s strategic objectives revolve around monetary exploitation. By stealing email credentials they can infiltrate internal networks, conduct fraudulent transactions, and sell access to third parties. The group targets sectors with high financial value or sensitive personal data—such as banking, government, defense, telecoms, healthcare, and energy—to maximize the potential payoff from compromised identities. Geographically, their focus on EU countries (Spain, Germany, Ukraine) reflects both the prevalence of vulnerable security practices and high-value corporate objectives in these markets.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
5
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
4
Tactics