Also known as: tracked as
Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering for initial access. They employ the AI-generated PowerShell backdoor Slopoly for persistent command-and-control access, which checks in with attacker infrastructure every 50 seconds and transmits telemetry every 30 seconds. The group leverages AzCopy for bulk data exfiltration to Azure blob storage before executing ransomware, employing a five-stage attack chain. Their operations are characterized by the use of initial access brokers and a variety of custom backdoors for long-term access and data exfiltration.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Hive0163 is a financially motivated ransomware group deploying the Interlock ransomware variant. The group employs social engineering (via ClickFix) for initial access, uses an AI-generated PowerShell backdoor (Slopoly) for persistence, and leverages AzCopy for data exfiltration to Azure storage. Their multi-stage attack chain includes data exfiltration prior to ransomware deployment, indicating a focus on maximizing impact for financial gain.
Goals & Targeting
Hive0163's primary objective is financial gain through ransomware attacks, focusing on organizations with high-value data and significant liquidity. The group typically targets sectors such as healthcare, manufacturing, and critical infrastructure, where operational disruptions can lead to rapid ransom payments. These sectors are also attractive due to their reliance on legacy systems and potential gaps in endpoint security. The actor's use of Azure-based exfiltration suggests a preference for cloud-dependent organizations, although no specific country targeting has been explicitly identified. Their multi-stage approach ensures thorough data exploitation before deploying ransomware, maximizing the likelihood of successful extortion.
Enhanced Description
Hive0163 operates as a financially driven ransomware group, deploying the Interlock ransomware variant to maximize extortion opportunities. The actor's initial access typically involves ClickFix, a social engineering tool, which facilitates spear-phishing campaigns targeting individuals within victim organizations. Once initial access is achieved, the group deploys Slopoly, an AI-generated PowerShell backdoor, to establish persistent command-and-control (C2) infrastructure. Slopoly communicates with attacker-controlled infrastructure every 50 seconds and transmits telemetry every 30 seconds, ensuring continuous monitoring of the compromised environment. The group's operational methodology includes a five-stage attack chain, with data exfiltration preceding ransomware deployment. This staging approach allows the actor to gather sensitive information for potential use in negotiations or to increase ransom demands. AzCopy, a Microsoft tool for large-scale data transfer, is leveraged for exfiltrating stolen data to Azure blob storage, indicating familiarity with cloud infrastructure and a strategic focus on resource-rich environments. The group's reliance on initial access brokers and custom backdoors underscores their intent to maintain long-term access to victim networks for extended data exfiltration or future attacks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Hive0163 operates with a high operational tempo, targeting organizations with weak endpoint defenses and reliance on cloud infrastructure. Campaigns typically involve spear-phishing with malicious documents, followed by rapid deployment of backdoors and data exfiltration using Azure tools. The group's use of AI in Slopoly suggests advanced technical capabilities and a focus on evading detection. Notable operations have involved targeting healthcare institutions and industrial organizations, with no evidence of nation-state ties or geopolitical motives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the identified capabilities and tools is medium to high, based on observed TTPs and attributed malware. However, gaps exist in confirming the full scope of Hive0163's operations, including their complete infrastructure and geographic targeting. The group's use of custom backdoors and AI tools suggests a level of sophistication that may be underreported in current intelligence.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
40
Tools
0
Campaigns
109
IOCs
0
Observed Data
5
Tactics