Special Bulletin
HHS OCIO HC3 TLP White Threat Briefing – Hive Ransomware – October 21, 2021
Agenda
• Hive Ransomware Overview
• Legitimate Applications and Closed Source Code
• Hive Ransomware Attacks
• Hive Ransomware Activity Targeting the U.S. HPH
• Hive Tactics, Techniques, and Procedures (TTPs)
• Mitigations
Overview
First observed in June 2021
• According to the Federal Bureau of Investigation (FBI), it “likely operates as an affiliate-based ransomware”
• Double extortion ransomware
• Human-operated attacks
• Uses legitimate commercial applications
• Utilizes their own closed-source ransomware (complied for both 32-bit and 64-bit machines)
• Possible Russian-speaking actors
View the entire report below.
For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:
John Riggi
Senior Advisor for Cybersecurity and Risk, AHA
jriggi@aha.org
(O) +1 202 626 2272
Key Resources
Related Resources
Guides and Reports
Advisory
Hospitals That Are Oracle Customers Urged to Take Immediate Action to Address Security Vulnerability
Issue Landing Page
Issue Landing Page
Guides and Reports