Hive ransomware actors extort over $100 mn from victims, warns US

by IANS |

San Francisco, Nov 19 (IANS) The US government has warned about an ongoing ransomware activity that has victimised over 1,300 companies worldwide, receiving approximately $100 million in ransom payments.

The Hive ransomware actors follow the ransomware-as-a-service (RaaS) model in which developers create, maintain, and update the malware, and affiliates conduct the ransomware attacks.

"From June 2021 through at least November 2022, threat actors have used Hive ransomware to target a wide range of businesses and critical infrastructure sectors, including government facilities, communications, critical manufacturing, information technology, and healthcare," read the joint advisory by the FBI, the US Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services.

The Hive actors have bypassed multi-factor authentication (MFA) and gained access to aFortiOS' servers by exploiting common vulnerabilities and exposures (CVE) CVE-2020-12812.

"This vulnerability enables a malicious cyber actor to log in without a prompt for the user's second authentication factor (FortiToken) when the actor changes the case of the username," according to the joint advisory.

Hive also attacked power generation company Tata Power in October. The Mumbai-based company had said that the attack impacted some of its IT systems.

Microsoft's Threat Intelligence Center (MSTIC) researchers have warned that Hive upgraded its malware, enabling it to use a more complex encryption method for its ransomware as a service payload.

"Hive actors negotiate ransom demands in US dollars, with initial amounts ranging from several thousand to millions of dollars. Hive actors demand payment in Bitcoin," according to the US advisory.

Latest News
Rajasthan Chief Justice inaugurates e-Facilities Centre Fri, Jul 26, 2024, 04:45 PM
Barack and Michelle Obama endorse Kamala Harris for US President Fri, Jul 26, 2024, 04:36 PM
Jonny Bairstow not ready to give up on England Test spot Fri, Jul 26, 2024, 04:26 PM
Thomas Partey hails Arsenal to 'avoid mistakes of last season' Fri, Jul 26, 2024, 03:58 PM
Changi Airport sees 13.4 per cent passenger increase in Q2 Fri, Jul 26, 2024, 03:44 PM
46 Kg of opium seized in Afghanistan, 3 arrested Fri, Jul 26, 2024, 03:27 PM
Over 6,20,000 affected by typhoon Gaemi in China Fri, Jul 26, 2024, 02:17 PM
Massive wildfires trigger evacuations, health alerts in US Fri, Jul 26, 2024, 02:04 PM
Philippines: One killed in Manila house fire Fri, Jul 26, 2024, 01:52 PM
LIC stock hits new lifetime high of Rs 1,178.60 Fri, Jul 26, 2024, 01:10 PM
'Street-smart' Suryakumar backed to rise up to India T20I captaincy challenge Fri, Jul 26, 2024, 01:08 PM
2 Indian military teams plant tri-colour on Mt. Elbrus in multinational military 'Climb for Peace' event Fri, Jul 26, 2024, 01:00 PM
iPhone exports from India touch new all-time high in April-June quarter Fri, Jul 26, 2024, 12:51 PM
Cong never respected Armed Forces, says BJP's Poonawalla on Kargil Vijay Diwas Fri, Jul 26, 2024, 12:48 PM
MyGov turns 10: Let's work towards a Viksit Bharat by 2047, says CEO Fri, Jul 26, 2024, 12:33 PM