Hive ransomware actors extort over $100 mn from victims, warns US

by IANS |

San Francisco, Nov 19 (IANS) The US government has warned about an ongoing ransomware activity that has victimised over 1,300 companies worldwide, receiving approximately $100 million in ransom payments.

The Hive ransomware actors follow the ransomware-as-a-service (RaaS) model in which developers create, maintain, and update the malware, and affiliates conduct the ransomware attacks.

"From June 2021 through at least November 2022, threat actors have used Hive ransomware to target a wide range of businesses and critical infrastructure sectors, including government facilities, communications, critical manufacturing, information technology, and healthcare," read the joint advisory by the FBI, the US Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services.

The Hive actors have bypassed multi-factor authentication (MFA) and gained access to aFortiOS' servers by exploiting common vulnerabilities and exposures (CVE) CVE-2020-12812.

"This vulnerability enables a malicious cyber actor to log in without a prompt for the user's second authentication factor (FortiToken) when the actor changes the case of the username," according to the joint advisory.

Hive also attacked power generation company Tata Power in October. The Mumbai-based company had said that the attack impacted some of its IT systems.

Microsoft's Threat Intelligence Center (MSTIC) researchers have warned that Hive upgraded its malware, enabling it to use a more complex encryption method for its ransomware as a service payload.

"Hive actors negotiate ransom demands in US dollars, with initial amounts ranging from several thousand to millions of dollars. Hive actors demand payment in Bitcoin," according to the US advisory.

Latest News
Wall collapse near historic Ahmedabad site: 2 dead, 3 injured, vehicles buried under debris Fri, Apr 19, 2024, 05:00 PM
Aurionpro Solutions to acquire PaaS startup Arya.ai Fri, Apr 19, 2024, 04:51 PM
Maha: 5 Vidarbha constituencies record 44.12 pc polling till 3 pm Fri, Apr 19, 2024, 04:49 PM
Football: Germany head coach Julian Nagelsmann signs contract extension until 2026 Fri, Apr 19, 2024, 04:44 PM
Sensex, Nifty witness worst week since March 15 amid Iran-Israel conflict Fri, Apr 19, 2024, 04:42 PM
Nigerian military kills 192 suspected terrorists in one week Fri, Apr 19, 2024, 04:38 PM
LS polls: Priyanka Gandhi to visit Kerala for campaigning on Saturday Fri, Apr 19, 2024, 04:34 PM
One crew member killed in Russian Tu-22M3 plane crash Fri, Apr 19, 2024, 04:28 PM
7 killed in fire in Indonesia's Jakarta Fri, Apr 19, 2024, 04:28 PM
30 injured in accident on Capri ferry in Naples Fri, Apr 19, 2024, 04:27 PM
German Chancellor urges against escalation in the Middle East Fri, Apr 19, 2024, 04:24 PM
Cops nab man for impersonating Lufthansa customer care executive, duping people Fri, Apr 19, 2024, 04:22 PM
Mizoram's sole LS seat records 50 per cent polling till 3 p.m. Fri, Apr 19, 2024, 04:19 PM
Over 43 pc voting in J&K's Kathua-Udhampur LS seat till 1 pm Fri, Apr 19, 2024, 04:17 PM
Tamil Nadu records 40.05 pc voting till 1 pm Fri, Apr 19, 2024, 04:02 PM