As of this month, Hive ransomware actors attacked over 1,300 companies worldwide, earning $100 million in ransom payments, said officials at the FBI.

Hive ransomware follows the ransomware-as-a-service (RaaS) model in which developers create, maintain, and update the malware, and affiliates conduct the ransomware attacks. From June 2021 through this month, attackers used Hive ransomware to target a wide range of businesses and critical infrastructure sectors, including critical manufacturing, government facilities, communications information technology, and healthcare and public health (HPH).

To that end, that is why the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) released a joint Cybersecurity Advisory (CSA) Thursday to disseminate known Hive tactics, techniques, and procedures (TTPs) and indicators of compromise (IoCs) identified through FBI investigations.

The method of initial intrusion will depend on which affiliate targets the network, according to the advisory. Hive actors have gained initial access to victim networks by using single factor logins via Remote Desktop Protocol (RDP), virtual private networks (VPNs), and other remote network connection protocols.

In some cases, Hive actors have bypassed multifactor authentication (MFA) and gained access to FortiOS servers by exploiting Common Vulnerabilities and Exposures (CVE) like CVE-2020-12812. This vulnerability enables a malicious cyber actor to log in without a prompt for the user’s second authentication factor (FortiToken) when the actor changes the case of the username.

Schneider Bold

Hive actors have also gained initial access to victim networks by distributing phishing emails with malicious attachments and by exploiting the following vulnerabilities against Microsoft Exchange servers:

  • CVE-2021-31207 — Microsoft Exchange Server security feature bypass vulnerability
  • CVE-2021-34473 — Microsoft Exchange Server remote code execution vulnerability
  • CVE-2021-34523 — Microsoft Exchange Server privilege escalation vulnerability

After gaining access, Hive ransomware attempts to evade detention by executing processes to:

  1. Identify processes related to backups, antivirus/anti-spyware, and file copying and then terminating those processes to facilitate file encryption
  2. Stop the volume shadow copy services and remove all existing shadow copies via vssadmin on command line or via PowerShell
  3. Delete Windows event logs, specifically the System, Security and Application logs

Prior to encryption, Hive ransomware removes virus definitions and disables all portions of Windows Defender and other common antivirus programs in the system registry, according to the advisory.

Hive actors exfiltrate data likely using a combination of Rclone and the cloud storage service Mega.nz. In addition to its capabilities against the Microsoft Windows operating system, Hive ransomware has known variants for Linux, VMware ESXi, and FreeBSD.

During the encryption process, a file named *.key (previously *.key.*) is created in the root directory (C:\ or /root/). Required for decryption, this key file only exists on the machine where it was created and cannot be reproduced. The ransom note, HOW_TO_DECRYPT.txt is dropped into each affected directory and states the *.key file cannot be modified, renamed, or deleted, otherwise the encrypted files cannot be recovered. The ransom note contains a “sales department” .onion link accessible through a TOR browser, enabling victim organizations to contact the actors through a live chat panel to discuss payment for their files. However, some victims reported receiving phone calls or emails from Hive actors directly to discuss payment.

The ransom note also threatens victims that a public disclosure or leak site accessible on the TOR site, “HiveLeaks”, contains data exfiltrated from victim organizations who do not pay the ransom demand. Additionally, Hive actors have used anonymous file sharing sites to disclose exfiltrated data.

Click here for more on the joint Cybersecurity Advisory.

ISSSource

Pin It on Pinterest

Share This