Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Hive0117

Also known as: Storm-0978, Tropical Scorpius, Smoke Sandstorm, TA455, aviation, tracked as, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Yellow Liderc, Tortoiseshell, defense industries, LuoYu, foreign entities, Qilin, file transfer tools, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Imperial Kitten, 0ktapus, UNC2596, Blue Echidna, GOFFEE, Fluffy Wolf, CASCADE PANDA, Octo Tempest, Scattered Spider, UNC961, Prophet Spider, Gamaredon, Shuckworm

Description

Hive0117, also referenced under several aliases—including Storm‑0978, Tropical Scorpius, TA455, and APT44—has been active in delivering financially driven operations that span an impressive portfolio of industrial and infrastructure sectors. The group’s offensive toolkit centers on sophisticated spear‑phishing vectors that combine crafted email templates, forged identities, and malicious archives (.RAR, .XPS) to trick users into executing fileless PowerShell loaders or embedded .NET assemblies. The threat actor leverages a mixture of known and zero‑day CVEs. Historically they have abused legacy Office exploits such as CVE‑2017‑11882 and CVE‑2017‑0199; more recently, the group has exploited the CVE‑2025‑8088 vulnerability in WinRAR to exfiltrate backdoors (SnipBot, RustyClaw, Mythic agent) into target environments via archive delivery. In addition to stealthy persistence mechanisms—including scheduled tasks and registry modification—the actor deploys data‑wiping wipers (ZEROLOT, Sting) and a suite of post‑exploitation tools like VBShower, Ghost RAT, Cobalt Strike, and the credential stealer MiniBrowse. Hive0117’s operations exhibit an emphasis on high-value targets across energy, defense, transportation, finance, manufacturing, and IT sectors in countries ranging from Russia and Kazakhstan to the United States, Canada, Israel, and Singapore. The group typically mimics official communications—such as conscription summons or government notices—to increase attachment click‑through and then harvest system information and credentials before establishing a persistent, covert foothold. The combination of fileless execution, credential theft, exploitation of both legacy and zero‑day vulnerabilities, and the use of sophisticated backdoors indicates that Hive0117 operates with moderate to advanced technical capabilities but remains primarily focused on monetary gain.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Manufacturing
Transportation
Critical infrastructure
Energy
Aerospace
Education
Healthcare
Retail
Media
Food agriculture
Aviation
Construction
Oil gas
Information technology
Entertainment
Utilities
Pharmaceutical
Chemical
Maritime
Mining
Legal services
Hospitality

Targeted Countries / Regions

RU
UA
US
CA
IR
BY
CN
KZ
BR
TW
GB
TR
IT
IL
EG
SG
VN
PL
PK
FR
DE
IN
MX
JP
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Hive0117 is a financially motivated threat actor primarily using spear‑phishing with malicious attachments and fileless PowerShell loaders to deliver backdoors such as DarkWatchman, SnipBot, RustyClaw, and Mythic agent. They exploit both legacy CVEs (e.g., CVE‑2017‑11882) and the zero‑day WinRAR vulnerability CVE‑2025‑8088 to penetrate a wide spectrum of industry sectors, especially energy, finance, defense, and manufacturing. These campaigns blend credential theft, data wiping wipers, and covert persistence via scheduled tasks—demonstrating moderate technical sophistication and a consistent focus on high-value, geographically diverse targets across Eastern Europe, the US, and Asia.

Goals & Targeting

Hive0117 seeks economic benefit through financial theft, data exfiltration, and sabotage. Their strategic objectives involve compromising secure, high-value environments—particularly those critical to national infrastructure—to harvest credentials for monetization or leverage within broader intrusion frameworks. They target organizations that are likely to respond to urgent bureaucratic communications, thereby increasing attack efficacy. The wide geographical scope reflects a systematic approach to identify vulnerable assets across multiple jurisdictions. Their targeting profile concentrates on entities in the energy, finance, defense, telecommunications, manufacturing, and transportation sectors where data can be monetized or used for coercive leverage.","key_capabilities":["Spear‑phishing via malicious archives (.RAR, .XPS) and link delivery","Social engineering through fake software updates and HR complaint lures","Exploitation of legacy document CVEs (CVE‑2017‑11882, CVE‑2017‑0199) and browser CVE‑2018‑6065","Zero‑day exploitation of WinRAR CVE‑2025‑8088 via path traversal and ADS injection","Fileless PowerShell loaders that decrypt shellcode in memory","Creation of scheduled tasks for persistence and wiper execution (ZEROLOT, Sting)","Delivery of VBShower dropper/backdoor through RTF/DOCX templates","Use of Ghost RAT for remote access","Deployment of Cobalt Strike beacons for espionage and financial operations","Distribution of backdoors: SnipBot variant, RustyClaw, Mythic agent, MiniJunk, DarkWatchman","Credential theft from Chrome/Edge using the MiniBrowse stealer"],

Enhanced Description

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. ics-cert.kaspersky.com — Cited by web research for: Crouching Yeti
  3. www.ibm.com — Cited by web research for: T1027.010
  4. www.cyber.gc.ca — Cited by web research for: Italy
  5. www.ibm.com — Cited by web research for: 103.153.157.33

Intel Summary

7

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

Phishing
Government Targeting
Financially motivated
Fileless malware
Social engineering
Eastern Europe
Critical Infrastructure

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.