Threat actor reference

Classification follows the source dataset. Metadata is useful. It is not testimony.

Actor lineage

Global lineage directory

Overview

The FBI infiltrated Hive infrastructure beginning in July 2022 and law enforcement seized servers and websites in January 2023. Disrupted does not mean every affiliate or derivative activity ended.

Documentary media

Known aliases

No source-supported alias is currently recorded. Malware names and actor-group names are not assumed to be equivalent.

Historical timeline

Lineage and relationships

No evidence-backed relationship is currently recorded. Similar code, language, infrastructure style, or negotiation behavior is not enough on its own.

Predecessors

None established.

Successors

None established.

Splits and mergers

None established.

Suspected affiliate relationships

None established.

Website seizure banners

Complete seizure archive

Explicit reviewed mappings connect the following seized.fyi records to this actor or a sourced lineage event. Seizure counts remain separate from negotiation, note, actor, and lineage statistics.

MITRE ATT&CK integration

No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.

External intelligence references

  1. U.S. Department of Justice Disrupts Hive Ransomware VariantU.S. Department of Justice · law enforcement · primary authoritative
  2. Mikhail Pavlovich MatveevFederal Bureau of Investigation · law enforcement · primary authoritative
  3. Russian National Charged with Ransomware Attacks Against Critical InfrastructureU.S. Department of Justice · law enforcement · primary authoritative
  4. Privacy PolicyFederal Bureau of Investigation · publisher terms · context only

Confidence and evidence notes

Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.

Search within this collection

Negotiation records

Filter Hive records

Collection: 8 records · 372 messages

Hive negotiation record collection
Participants Source Archive status
20211220 24 Hive, Victim JSON Indexed
20211213 15 Hive, Victim JSON Indexed
20211126 4 Hive JSON Indexed
20211113 136 Hive, Victim JSON Indexed
20211102 58 Hive, Victim JSON Indexed
20211026 46 Hive, Victim JSON Indexed
20211005 19 Hive, Victim JSON Indexed
20211004 70 Hive, Victim JSON Indexed