Hive0163 is a financially motivated group known for deploying Interlock ransomware via ClickFix social engineering.
Analyst brief
Hive0163 is a financially motivated ransomware group deploying Interlock ransomware, using ClickFix social engineering for initial access. They target organizations for financial gain, conducting bulk data exfiltration to Azure blob storage via AzCopy before encrypting files. Key TTPs include the AI-generated Slopoly PowerShell backdoor (checks C2 every 50 seconds), a five-stage attack chain, and reliance on initial access brokers. Defenders should monitor for unusually timed PowerShell network connections, AzCopy usage, and signs of ClickFix social engineering attempts.
Hive0163
unknown
Hive0163 is a financially motivated ransomware group responsible for deploying Interlock ransomware, utilizing ClickFix social engineering for initial access. They employ the AI-generated PowerShell backdoor Slopoly for persistent command-and-control access, which checks in with attacker infrastructure every 50 seconds and transmits telemetry every 30 seconds. The group leverages AzCopy for bulk data exfiltration to Azure blob storage before executing ransomware, employing a five-stage attack chain. Their operations are characterized by the use of initial access brokers and a variety of custom backdoors for long-term access and data exfiltration.