FlagThis
← Threat Actors
/
Global
/
Hive0163
DOSSIER // HIVE0163
Hive0163
ACTIVE CAMPAIGN TRACKED
⚠ Critical Threat
Primary Aliases:
No secondary vendor aliases recorded.
Sponsor / State Affiliation
Independent / Not Attributed
Primary Motivation
Financial extortion through large-scale data exfiltration and ransomware encryption.
Active Timeline
Unknown – Present
Confidence Rating
90% (Grounded)
Slopoly/Interlock Ransomware Campaign, Cisco FMC Zero-Day Exploitation
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(1)
CVE-2026-20131
Weaponized Vulnerability
CVSS 8.5
KEV
EPSS 85.0%
📋 Copy CSV
Tenable Nessus
Qualys / Wiz
🎯 Target Sectors & Focus
Healthcare
Education
Government
Critical Infrastructure
Financial Services
🛡️ MITRE ATT&CK® Attack Lifecycle
(9 TTPs)
📥 Download Navigator JSON
All Stages
9
Initial Access
1
Execution
1
Defense Evasion
1
Credential Access & Discovery
2
Command & Control
2
Exfiltration & Impact
1
Operational Techniques
1
Initial Access
1
T1566
Exploitation of Public-Facing Applications (e.g., CVE-2026-20131)
↗
Execution
1
T1059
PowerShell-based Persistence (Scheduled Tasks)
↗
Defense Evasion
1
T1027
Defense Evasion (EDR/AV suppression)
↗
Credential Access & Discovery
2
T1003
Social Engineering (ClickFix)
↗
T1003
Credential Theft (LSASS dumping)
↗
Command & Control
2
T1071
Remote Access Trojans (NodeSnake, Interlock RAT)
↗
T1071
Data Exfiltration
↗
Exfiltration & Impact
1
T1485
Double Extortion
↗
Operational Techniques
1
T1000
AI-Assisted Malware Development (Slopoly)
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Adversary Rosetta Stone // Hive0163
×
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD