Hive
From extortion.wiki, the ransomware negotiation research archive
Negotiation records classified under Hive in the current Ransomchats snapshot. This page indexes the source label; it does not independently verify attribution.
Classification follows the source dataset. Metadata is useful. It is not testimony.
Actor lineage
Global lineage directoryOverview
The FBI infiltrated Hive infrastructure beginning in July 2022 and law enforcement seized servers and websites in January 2023. Disrupted does not mean every affiliate or derivative activity ended.
Documentary media

Known aliases
No source-supported alias is currently recorded. Malware names and actor-group names are not assumed to be equivalent.
Historical timeline
-
No verified documentary image available. Hive first observed
Hive activity documented
DOJ reports that Hive targeted victims from June 2021.
Evidence status: source-supported observation Confirmed -
No verified documentary image available. Hive infrastructure disrupted
FBI infiltration begins
DOJ says the FBI penetrated Hive's networks in late July 2022 and began providing decryption keys to victims.
Evidence status: official disruption record Confirmed -
No verified documentary image available. Hive leak site seized
Hive servers and websites seized
DOJ announced that U.S., German, and Dutch authorities seized control of Hive servers and websites, disrupting its ability to attack and extort victims.
Evidence status: official disruption record ConfirmedSeizure banners: Hive
Lineage and relationships
No evidence-backed relationship is currently recorded. Similar code, language, infrastructure style, or negotiation behavior is not enough on its own.
Predecessors
None established.
Successors
None established.
Splits and mergers
None established.
Suspected affiliate relationships
None established.
Website seizure banners
Complete seizure archiveExplicit reviewed mappings connect the following seized.fyi records to this actor or a sourced lineage event. Seizure counts remain separate from negotiation, note, actor, and lineage statistics.
MITRE ATT&CK integration
No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.
External intelligence references
- U.S. Department of Justice Disrupts Hive Ransomware VariantU.S. Department of Justice · law enforcement · primary authoritative
- Mikhail Pavlovich MatveevFederal Bureau of Investigation · law enforcement · primary authoritative
- Russian National Charged with Ransomware Attacks Against Critical InfrastructureU.S. Department of Justice · law enforcement · primary authoritative
- Privacy PolicyFederal Bureau of Investigation · publisher terms · context only
Confidence and evidence notes
Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.
Ransomware notes
Browse Hive notesThe explicit archive alias mapping connects this Ransomchats actor label to the ThreatLabz family Hive. Its 2 archived notes are counted and searched separately from the negotiation records below.
Search within this collection
Negotiation records
| Participants | Source | Archive status | |||
|---|---|---|---|---|---|
| 20211220 | 24 | Hive, Victim | JSON | Indexed | |
| 20211213 | 15 | Hive, Victim | JSON | Indexed | |
| 20211126 | 4 | Hive | JSON | Indexed | |
| 20211113 | 136 | Hive, Victim | JSON | Indexed | |
| 20211102 | 58 | Hive, Victim | JSON | Indexed | |
| 20211026 | 46 | Hive, Victim | JSON | Indexed | |
| 20211005 | 19 | Hive, Victim | JSON | Indexed | |
| 20211004 | 70 | Hive, Victim | JSON | Indexed |
No matching records
No records match the current filters. Remove one before blaming the archive.