City
Epaper

Hive ransomware actors extort over $100 mn from victims, warns US

By IANS | Published: November 19, 2022 9:00 AM

San Francisco, Nov 19 The US government has warned about an ongoing ransomware activity that has victimised over ...

Open in App

San Francisco, Nov 19 The US government has warned about an ongoing ransomware activity that has victimised over 1,300 companies worldwide, receiving approximately $100 million in ransom payments.

The Hive ransomware actors follow the ransomware-as-a-service (RaaS) model in which developers create, maintain, and update the malware, and affiliates conduct the ransomware attacks.

"From June 2021 through at least November 2022, threat actors have used Hive ransomware to target a wide range of businesses and critical infrastructure sectors, including government facilities, communications, critical manufacturing, information technology, and healthcare," read the joint advisory by the FBI, the US Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services.

The Hive actors have bypassed multi-factor authentication (MFA) and gained access to aFortiOS' servers by exploiting common vulnerabilities and exposures (CVE) CVE-2020-12812.

"This vulnerability enables a malicious cyber actor to log in without a prompt for the user's second authentication factor (FortiToken) when the actor changes the case of the username," according to the joint advisory.

Hive also attacked power generation company Tata Power in October. The Mumbai-based company had said that the attack impacted some of its IT systems.

Microsoft's Threat Intelligence Center (MSTIC) researchers have warned that Hive upgraded its malware, enabling it to use a more complex encryption method for its ransomware as a service payload.

"Hive actors negotiate ransom demands in US dollars, with initial amounts ranging from several thousand to millions of dollars. Hive actors demand payment in Bitcoin," according to the US advisory.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: National Cybersecurity and Communications Integration CenterusSan FranciscoFBISan francisco bayJose d'sa
Open in App

Related Stories

InternationalUS: One Passenger Shot Dead, Suspect in Custody After Hijacked Bus Pursuit in Georgia; Watch Videos

InternationalUS Fire: Over 1.2 Million Chickens Burn to Death in Massive Blaze at Egg Facility in Illinois (Watch Video)

NationalAir India Receives DGCA's Show Cause Notice Following 20-Hour Delay of Delhi to San Francisco Flight

InternationalOhio Chase Bank Blast: One Dead, Multiple Injured After Gas Leak Explosion in Youngstown Building; Dramatic Video Emerges

MaharashtraGanesh Chaturthi 2024: Pen's Ganpati Bappa Goes Global as Fifth Batch of 5,000 Idols Shipped to Canada and America

Technology Realted Stories

TechnologyIndian corporates' large capex to need offshore funding amid steady economic growth

TechnologyIndia's 500 GW renewable energy target to require investment up to $215 bn in 7 years

TechnologyExperts express concern over bird flu spread in house mice, domestic cats in US

Technology86 pc of firms globally experimenting with GenAI for innovation: Report

TechnologyEU slaps extra tariffs of up to 38 per cent on Chinese EVs