Hive Hackers Are Exploiting Microsoft Exchange Servers In Ransomware Spree
First spotted in June 2021, Hive is a Ransomware-as-a-Service (RaaS) model in which cyberattackers can utilize the Hive ransomware strain in attacks. The threat actors operate a leak site, accessible via a .onion address, which aims to ’name and shame’ ransomware victims. Additionally, the malware operators practice double-extortion, in which sensitive corporate data is stolen from a victim organization before disk encryption. If a victim refuses to pay for a decryption key, the cyberattackers will plaster their name across the leak site and set a timer before the data is leaked....