threatintel
actor tracker
IOC pivot
ioc · name

HOW_TO_DECRYPT.txt

?? · UnknownHiveconfidence · high

Hive ransom note dropped into every encrypted directory; instructs victims not to modify the *.key file in C:\ or /root and links to the HiveLeaks Tor chat panel. Listed in Table 2 of joint FBI/CISA/HHS advisory AA22-321A (Nov. 17, 2022).

family
Hive
first seen
Nov 16, 2022
publisher
CISA
source citation