23/02/2022
Hive, like other cybercriminals groups, operates a ransomware-as-a-service that uses different mechanisms to compromise business networks, exfiltrate data, and encrypt data on the networks, and attempts to collect a ransom in exchange for access to the decryption software.
It was first observed in June 2021, when it struck a company called Altus Group. Hive leverages a variety of initial compromise methods including vulnerable RDP servers, compromised VPN credentials, as well as phishing.