Also known as: Storm-0978, Tropical Scorpius, Smoke Sandstorm, TA455, aviation, tracked as, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, SHADOW-VOID-042, RomCom, the Bulldog backdoor, defense-industry organizations, Yellow Liderc, Tortoiseshell, defense industries, LuoYu, foreign entities, Qilin, file transfer tools, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Imperial Kitten, 0ktapus, UNC2596, Blue Echidna, GOFFEE, Fluffy Wolf, CASCADE PANDA, Octo Tempest, Scattered Spider, UNC961, Prophet Spider, Gamaredon, Shuckworm
Hive0117, also referenced under several aliases—including Storm‑0978, Tropical Scorpius, TA455, and APT44—has been active in delivering financially driven operations that span an impressive portfolio of industrial and infrastructure sectors. The group’s offensive toolkit centers on sophisticated spear‑phishing vectors that combine crafted email templates, forged identities, and malicious archives (.RAR, .XPS) to trick users into executing fileless PowerShell loaders or embedded .NET assemblies. The threat actor leverages a mixture of known and zero‑day CVEs. Historically they have abused legacy Office exploits such as CVE‑2017‑11882 and CVE‑2017‑0199; more recently, the group has exploited the CVE‑2025‑8088 vulnerability in WinRAR to exfiltrate backdoors (SnipBot, RustyClaw, Mythic agent) into target environments via archive delivery. In addition to stealthy persistence mechanisms—including scheduled tasks and registry modification—the actor deploys data‑wiping wipers (ZEROLOT, Sting) and a suite of post‑exploitation tools like VBShower, Ghost RAT, Cobalt Strike, and the credential stealer MiniBrowse. Hive0117’s operations exhibit an emphasis on high-value targets across energy, defense, transportation, finance, manufacturing, and IT sectors in countries ranging from Russia and Kazakhstan to the United States, Canada, Israel, and Singapore. The group typically mimics official communications—such as conscription summons or government notices—to increase attachment click‑through and then harvest system information and credentials before establishing a persistent, covert foothold. The combination of fileless execution, credential theft, exploitation of both legacy and zero‑day vulnerabilities, and the use of sophisticated backdoors indicates that Hive0117 operates with moderate to advanced technical capabilities but remains primarily focused on monetary gain.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Hive0117 is a financially motivated threat actor primarily using spear‑phishing with malicious attachments and fileless PowerShell loaders to deliver backdoors such as DarkWatchman, SnipBot, RustyClaw, and Mythic agent. They exploit both legacy CVEs (e.g., CVE‑2017‑11882) and the zero‑day WinRAR vulnerability CVE‑2025‑8088 to penetrate a wide spectrum of industry sectors, especially energy, finance, defense, and manufacturing. These campaigns blend credential theft, data wiping wipers, and covert persistence via scheduled tasks—demonstrating moderate technical sophistication and a consistent focus on high-value, geographically diverse targets across Eastern Europe, the US, and Asia.
Goals & Targeting
Hive0117 seeks economic benefit through financial theft, data exfiltration, and sabotage. Their strategic objectives involve compromising secure, high-value environments—particularly those critical to national infrastructure—to harvest credentials for monetization or leverage within broader intrusion frameworks. They target organizations that are likely to respond to urgent bureaucratic communications, thereby increasing attack efficacy. The wide geographical scope reflects a systematic approach to identify vulnerable assets across multiple jurisdictions. Their targeting profile concentrates on entities in the energy, finance, defense, telecommunications, manufacturing, and transportation sectors where data can be monetized or used for coercive leverage.","key_capabilities":["Spear‑phishing via malicious archives (.RAR, .XPS) and link delivery","Social engineering through fake software updates and HR complaint lures","Exploitation of legacy document CVEs (CVE‑2017‑11882, CVE‑2017‑0199) and browser CVE‑2018‑6065","Zero‑day exploitation of WinRAR CVE‑2025‑8088 via path traversal and ADS injection","Fileless PowerShell loaders that decrypt shellcode in memory","Creation of scheduled tasks for persistence and wiper execution (ZEROLOT, Sting)","Delivery of VBShower dropper/backdoor through RTF/DOCX templates","Use of Ghost RAT for remote access","Deployment of Cobalt Strike beacons for espionage and financial operations","Distribution of backdoors: SnipBot variant, RustyClaw, Mythic agent, MiniJunk, DarkWatchman","Credential theft from Chrome/Edge using the MiniBrowse stealer"],
Enhanced Description
No campaigns linked yet.
No observed data linked yet.
7
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics