H-ISAC TLP White: FBI Releases Indicators of Compromise Associated with Hive Ransomware 8-26-21

H-ISAC TLP White Finished Intelligence Report: FBI Releases Indicators of Compromise Associated with Hive Ransomware August 26, 2021

The US Federal Bureau of Investigation (FBI) has released a FLASH advisory reporting technical details and indicators of compromise (IOCs) associated with the Hive ransomware group.

Hive ransomware, which was first observed in June 2021 and likely operates as affiliate-based ransomware, employs a wide variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Hive ransomware uses multiple mechanisms to compromise business networks, including phishing emails with malicious attachments to gain access and Remote Desktop Protocol (RDP) to move laterally once on the network.

After compromising a victim network, Hive ransomware actors exfiltrate data and encrypt files on the network. The actors leave a ransom note in each affected directory within a victim’s system, which provides instructions on how to purchase the decryption software. The ransom note also threatens to leak exfiltrated victim data on the Tor site, HiveLeaks.

Please see the attached FBI Flash for additional insight, technical details, and IOCs.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

Senior Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272