Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Hive0163

Also known as: tracked as

Description

Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering for initial access. They employ the AI-generated PowerShell backdoor Slopoly for persistent command-and-control access, which checks in with attacker infrastructure every 50 seconds and transmits telemetry every 30 seconds. The group leverages AzCopy for bulk data exfiltration to Azure blob storage before executing ransomware, employing a five-stage attack chain. Their operations are characterized by the use of initial access brokers and a variety of custom backdoors for long-term access and data exfiltration.

Goals & Targeting

Targeted Sectors

Financial services
Healthcare
Manufacturing
Energy
Mining
Utilities

Targeted Countries / Regions

IR
US
GB
KR
RU

AI Analysis

· 1 week ago

Executive Summary

Hive0163 is a financially motivated ransomware group deploying the Interlock ransomware variant. The group employs social engineering (via ClickFix) for initial access, uses an AI-generated PowerShell backdoor (Slopoly) for persistence, and leverages AzCopy for data exfiltration to Azure storage. Their multi-stage attack chain includes data exfiltration prior to ransomware deployment, indicating a focus on maximizing impact for financial gain.

Goals & Targeting

Hive0163's primary objective is financial gain through ransomware attacks, focusing on organizations with high-value data and significant liquidity. The group typically targets sectors such as healthcare, manufacturing, and critical infrastructure, where operational disruptions can lead to rapid ransom payments. These sectors are also attractive due to their reliance on legacy systems and potential gaps in endpoint security. The actor's use of Azure-based exfiltration suggests a preference for cloud-dependent organizations, although no specific country targeting has been explicitly identified. Their multi-stage approach ensures thorough data exploitation before deploying ransomware, maximizing the likelihood of successful extortion.

Enhanced Description

Hive0163 operates as a financially driven ransomware group, deploying the Interlock ransomware variant to maximize extortion opportunities. The actor's initial access typically involves ClickFix, a social engineering tool, which facilitates spear-phishing campaigns targeting individuals within victim organizations. Once initial access is achieved, the group deploys Slopoly, an AI-generated PowerShell backdoor, to establish persistent command-and-control (C2) infrastructure. Slopoly communicates with attacker-controlled infrastructure every 50 seconds and transmits telemetry every 30 seconds, ensuring continuous monitoring of the compromised environment. The group's operational methodology includes a five-stage attack chain, with data exfiltration preceding ransomware deployment. This staging approach allows the actor to gather sensitive information for potential use in negotiations or to increase ransom demands. AzCopy, a Microsoft tool for large-scale data transfer, is leveraged for exfiltrating stolen data to Azure blob storage, indicating familiarity with cloud infrastructure and a strategic focus on resource-rich environments. The group's reliance on initial access brokers and custom backdoors underscores their intent to maintain long-term access to victim networks for extended data exfiltration or future attacks.

Key Capabilities

  • Social engineering campaigns via ClickFix for initial access
  • Deployment of AI-generated PowerShell backdoor (Slopoly) for persistence
  • Utilization of AzCopy for large-scale data exfiltration to Azure blob storage
  • Execution of multi-stage attack chains with data exfiltration prior to ransomware deployment
  • Leverage of initial access brokers for initial compromise
  • Custom backdoor implementation for long-term network access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Data Exfiltration
Impact

ATT&CK Techniques

T1059.003 - PowerShell for lateral movement and persistence
T1560.001 - Exfiltration via cloud storage (Azure)
T1038 - Exploiting credentials through stolen password hashes
T1486 - Data encryption for impact
T1055 - Remote code execution via malicious documents
T1566.001 - Deception using fake updates or files

Software / Tooling

ClickFix
Slopoly (AI-generated PowerShell backdoor)
AzCopy
Interlock ransomware

Campaigns & Victims

Hive0163 operates with a high operational tempo, targeting organizations with weak endpoint defenses and reliance on cloud infrastructure. Campaigns typically involve spear-phishing with malicious documents, followed by rapid deployment of backdoors and data exfiltration using Azure tools. The group's use of AI in Slopoly suggests advanced technical capabilities and a focus on evading detection. Notable operations have involved targeting healthcare institutions and industrial organizations, with no evidence of nation-state ties or geopolitical motives.

IOC Patterns

  • Spear-phishing emails containing macro-laced Office documents
  • C2 communication via PowerShell with 50-second intervals
  • Data exfiltration using AzCopy to Azure blob storage
  • Presence of Slopoly backdoor with telemetry transmission every 30 seconds
  • Ransomware deployment after staged data exfiltration

Recommended Actions

  • Implement advanced phishing detection measures to block ClickFix-based spear-phishing campaigns
  • Monitor PowerShell activity for anomalous execution patterns indicative of Slopoly
  • Restrict AzCopy usage to prevent unauthorized cloud data exfiltration
  • Deploy endpoint detection and response (EDR) tools to identify AI-driven backdoors
  • Conduct regular backups and ensure offline storage of critical data to mitigate ransomware impact

Suggested Tags

ransomware
financially motivated
critical infrastructure targeting
cloud exploitation
AI-powered tools

Confidence Assessment

Confidence in the identified capabilities and tools is medium to high, based on observed TTPs and attributed malware. However, gaps exist in confirming the full scope of Hive0163's operations, including their complete infrastructure and geographic targeting. The group's use of custom backdoors and AI tools suggests a level of sophistication that may be underreported in current intelligence.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 12 Filename 6 URL 2

References

  1. www.decryptiondigest.com — Cited by web research for: T1053.005
  2. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  3. securityaffairs.com — Cited by web research for: INC Ransomware
  4. www.escudodigital.com — Cited by web research for: Persistence mechanisms
  5. www.europol.europa.eu — Cited by web research for: US

Intel Summary

9

Techniques

40

Tools

0

Campaigns

109

IOCs

0

Observed Data

5

Tactics

Tags

Ransomware
Backdoor / C2
Data Exfiltration
ransomware
financially motivated
critical infrastructure targeting
cloud exploitation
AI-powered tools

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.