The Hive ransomware group crossed a significant milestone earlier this week, the Cybersecurity Infrastructure and Safety Company (CISA) stated in a joint press launch, revealed along with the Federal Bureau of Investigation (FBI) and the Division of Well being and Human Companies (HHS).
In response to the assertion, since June 2021 the group managed to contaminate greater than 1,300 firms with its ransomware variant and raked in north of $100 million for its efforts.
What’s extra, the group doesn’t appear to take no for a solution. The three companies found Hive reinfecting these victims that select to revive their networks as an alternative of paying the ransom demand.
Reinfecting rebellious victims
“Hive actors have been identified to reinfect—with both Hive ransomware or one other ransomware variant—the networks of sufferer organizations who’ve restored their community with out making a ransom fee,” the press launch reads.
Hive additionally casts a comparatively extensive internet, when looking for new victims. Whereas it’s considerably centered on Healthcare and Public Well being (PHP) organizations, it does take pleasure in an occasional authorities entity, communications agency, or IT firm.
The three organizations are typically in opposition to paying the ransom demand, as that doesn’t assure they’ll get the decryption key, or the stolen knowledge again. On the flip facet, it is going to most undoubtedly inspire the group (and different, related teams, too) to proceed attacking, proceed deploying ransomware, and proceed asking for more cash.
As a substitute, they urge the victims to report the assault to their native FBI discipline workplace or attain out to CISA through e-mail.
These experiences, it says within the launch, will assist regulation enforcement collect key knowledge that’s wanted to remain on Hive’s path, disrupt potential future assaults, and in the end – deliver the menace actors to justice.
Hive was first noticed within the early summer time of final yr.
Through BleepingComputer (opens in new tab)