Skip to main content
Mallory
1 malware family

Hive0117

Also known asHive0117

Hive0117 is a financially motivated threat group active since at least late 2021. It primarily targets corporate finance and accounting departments in order to gain access to corporate remote banking systems and steal money. Reported victim organizations were primarily in Russia, with additional victims or prior targeting noted in Belarus, Kazakhstan, Uzbekistan, Lithuania, and Estonia. F6 reported roughly 400 successful attacks against Russian organizations since the start of the year in one 2026 reporting period. Hive0117 is associated with phishing campaigns that use accounting- and business-themed lures, including invoices, reconciliation statements, waybills, payment debt notices, shipping paperwork, and in one 2023 campaign, fake military conscription notices impersonating Russian government communications. The group sends password-protected RAR archives, with the password included in the email body, containing malicious files disguised as financial documents. These infections deploy the fileless malware DarkWatchman, which has been linked to Hive0117 since at least 2021. DarkWatchman is used to establish covert access, and in observed campaigns it downloaded a keylogger module that intercepted keystrokes, monitored clipboard contents, and tracked connection of cryptographic tokens used for corporate banking access. When banking-related access is available, Hive0117 proceeds with follow-on tooling including remote access tools such as LiteManager, BitRAT, and malware with hVNC functionality, allowing hidden control of victim systems through a virtual desktop. The group then accesses corporate online banking portals directly from compromised accountant workstations so activity appears legitimate. In the 2026 campaign, researchers reported a shift from direct transfers to fraudulent payroll-register payments: payment orders were made to look like salary disbursements to employees while actually routing funds to attacker-controlled drop accounts. Reported losses increased from an average of 3 million rubles to 10 million rubles, and the largest confirmed theft in the campaign exceeded 14 million rubles. No additional aliases or sub-groups were provided in the source content, and the group's origin remains unknown. F6 assessed its operations as financially motivated rather than connected to the broader Russia-Ukraine cyber conflict.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Banks
  • Software & Services
  • Capital Goods
  • Consumer Discretionary Distribution & Retail
  • Materials
  • Food, Beverage & Tobacco

Where they target

Geographies tied to known operations.

  • 🇷🇺 Russia
  • 🇧🇾 Belarus
  • 🇰🇿 Kazakhstan
  • 🇺🇿 Uzbekistan
MITRE ATT&CK

Tradecraft

12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics20 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1566×2
Phishing
T1566.001×2
Spearphishing Attachment
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
2 techniques
T1036
Masquerading
T1078
Valid Accounts
TA0006
Credential Access
1 technique
T1056
Input Capture
T1056.001
Keylogging
TA0007
Discovery
1 technique
T1120
Peripheral Device Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.005
VNC
TA0009
Collection
3 techniques
T1056
Input Capture
T1056.001
Keylogging
T1115
Clipboard Data
T1560
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
2 techniques
T1105
Ingress Tool Transfer
T1219×2
Remote Access Tools
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping12

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.