{"id":46334,"date":"2022-04-21T11:33:00","date_gmt":"2022-04-21T11:33:00","guid":{"rendered":"http:\/\/9e83e83a-23e4-498f-89ab-4ca464f2ce4b"},"modified":"2022-04-21T11:33:00","modified_gmt":"2022-04-21T11:33:00","slug":"hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/","title":{"rendered":"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree"},"content":{"rendered":"<div class=\"share-bar-wrapper\">\n<div class=\"full-byline\">\n<div class=\"author-avatars\"> <a rel=\"author\" class=\"thumb author-modal-open\" data-component=\"authorModal\" data-author-modal-options=\"{&quot;selector&quot;:&quot;charlie-osborne-modal&quot;,&quot;hoverSelector&quot;:&quot;.full-byline&quot;}\" href=\"https:\/\/www.zdnet.com\/meet-the-team\/us\/charlie-osborne\/\" data-vanity-rewritten=\"true\"> <span class=\"img \"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/c8ef739a72ea5f7507a32fca52940befe437ac45\/2014\/07\/22\/36b8334d-1175-11e4-9732-00505685119a\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp\" class alt=\"Charlie Osborne\" height=\"50\" width=\"50\"><\/span> <\/a> <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/f427c952e8209ba6cc2c7e4545a4f1189c905424\/2022\/04\/21\/a67dc903-cd05-47dc-8068-10c19abfce08\/screenshot-2022-04-21-at-11-37-50.png?width=1200&amp;fit=bounds&amp;format=pjpg&amp;auto=webp\" class alt=\"screenshot-2022-04-21-at-11-37-50.png\" height=\"auto\" width=\"1200\"><\/span><figcaption><span class=\"caption\"><\/span><\/figcaption><\/figure>\n<p>The Hive threat group is targeting vulnerable Microsoft Exchange Servers to deploy ransomware.<\/p>\n<p>First spotted in June 2021, Hive is a Ransomware-as-a-Service (RaaS) model in which cyberattackers can utilize the Hive ransomware strain in attacks.<\/p>\n<p>The threat actors operate a leak site, accessible via a .onion address, which aims to &#8216;name and shame&#8217; ransomware victims. Additionally, the malware operators practice double-extortion, in which sensitive corporate data is stolen from a victim organization before disk encryption. <\/p>\n<p>If a victim refuses to pay for a decryption key, the cyberattackers will plaster their name across the leak site and set a timer before the data is leaked. This piles on the pressure and gives the attackers more opportunities for extortion. <\/p>\n<p>Hive&#8217;s past victims include non-profit entities, the energy sector, financial companies, and healthcare providers.<\/p>\n<p>&#8220;While some ransomware groups operating as RaaS networks claim to steer clear of targeting specific sectors such as hospitals or other critical industries to avoid causing harm to people, Hive&#8217;s attacks against healthcare providers in 2021 showed that the operators behind it have no regard for such humanitarian considerations,&#8221; Trend Micro said in a <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/ransomware-spotlight\/ransomware-spotlight-hive\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">March 2022 investigation<\/a> of the group. <\/p>\n<p>The FBI issued an alert on Hive activity in August 2021, followed by the <a href=\"https:\/\/www.hhs.gov\/sites\/default\/files\/hive-ransomware-analyst-note-tlpwhite.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">HHS this April<\/a> (.PDF), who cautioned that the RaaS outfit is an &#8220;exceptionally aggressive, financially-motivated ransomware group.&#8221; <\/p>\n<p>In new research published on April 19 by the <a href=\"https:\/\/www.varonis.com\/blog\/hive-ransomware-analysis\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Varonis Forensics Team<\/a>, a recent ransomware incident has allowed the company to examine the group&#8217;s tactics and procedures in depth. <\/p>\n<p>An unnamed customer&#8217;s networks were infiltrated, and the attack was complete in 72 hours. <\/p>\n<p>The intrusion began with the exploitation of ProxyShell, a <a href=\"https:\/\/www.zdnet.com\/article\/everything-you-need-to-know-about-microsoft-exchange-server-hack\/\" target=\"_blank\" rel=\"noopener\">set of critical vulnerabilities<\/a> in the Microsoft Exchange Server patched by the vendor in 2021. The security flaws could lead to the remote, full compromise of Exchange servers. <\/p>\n<p>Once exploited, a webshell backdoor is executed to maintain persistence and grant the attack group a path into the server to deploy Powershell code with SYSTEM-level privileges. <\/p>\n<p>Hive launches a Cobalt Strike beacon in the next step and creates a new administrator user account. Mimikatz comes into play, and the domain Administrator NTLM hash is stolen. <\/p>\n<p>&#8220;By stealing the domain Administrator NTLM hash and without needing to crack the password, the operator managed to reuse it via Pass-The-Hash attack and take control of the domain admin account,&#8221; the researchers say. <\/p>\n<p>Pass-The-Hash techniques can dupe a target system into launching authenticated sessions on a network without requiring a password crack. <\/p>\n<p>Hive will then perform reconnaissance on the server, collect information, and deploy the ransomware payload. <\/p>\n<p>The Go-based Hive ransomware payload, buried in a file called &#8220;windows.exe,&#8221; will encrypt files, delete shadow copies, disable security solutions, and clear Windows event logs. The malware will also try to disable the Windows Security Accounts Manager (SAM) to stop alerts from being sent to SIEM. <\/p>\n<p>Once encryption is complete, Hive posts a ransomware note, telling its victim that all data is encrypted and files have been stolen. <\/p>\n<p>Hive then urges its victim to contact the &#8220;sales department&#8221; at a .onion address accessible via the Tor network to gain an encryption key and stop &#8220;personal data, financial reports, and important documents&#8221; from being leaked online. <\/p>\n<p>Hive then provides instructions and a set of &#8216;guidelines&#8217; for organizations to follow, including: <\/p>\n<ul>\n<li>Do not modify, rename or delete *.key. files. Your data will be undecryptable.<\/li>\n<li>Do not modify or rename encrypted files. You will lose them.<\/li>\n<li>Do not report to the Police, FBI, etc. They don&#8217;t care about your business. They simply won&#8217;t allow you to pay. As a result, you will lose everything.<\/li>\n<\/ul>\n<p>&#8220;Ransomware attacks have grown significantly over the past years and remain the preferred method of threat actors aiming to maximize profits,&#8221; the researchers say. &#8220;The impact of an attack can be detrimental. It may potentially harm an organization&#8217;s reputation, disrupt regular operations and lead to temporary, and possibly permanent, loss of sensitive data.&#8221; <\/p>\n<p>Varonis recommends that system administrators make sure their Exchange servers have been patched. Admins may also wish to enforce frequent password rotations, block SMBv1, and use SMB signing. <\/p>\n<p>It is also recommended that organizations consider zero-trust models to restrict employee account privileges to only access the resources they need in their roles, thereby reducing the potential attack surface if the account is compromised. &nbsp; <\/p>\n<p><strong>See also<\/strong><\/p>\n<hr>\n<p><strong>Have a tip?<\/strong> Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0<\/p>\n<hr>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In one case, it took them less than 72 hours to infiltrate and hold a company to ransom.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-46334","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-04-21T11:33:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/a\/img\/resize\/c8ef739a72ea5f7507a32fca52940befe437ac45\/2014\/07\/22\/36b8334d-1175-11e4-9732-00505685119a\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree\",\"datePublished\":\"2022-04-21T11:33:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/\"},\"wordCount\":746,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/c8ef739a72ea5f7507a32fca52940befe437ac45\\\/2014\\\/07\\\/22\\\/36b8334d-1175-11e4-9732-00505685119a\\\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/\",\"name\":\"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/c8ef739a72ea5f7507a32fca52940befe437ac45\\\/2014\\\/07\\\/22\\\/36b8334d-1175-11e4-9732-00505685119a\\\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp\",\"datePublished\":\"2022-04-21T11:33:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/c8ef739a72ea5f7507a32fca52940befe437ac45\\\/2014\\\/07\\\/22\\\/36b8334d-1175-11e4-9732-00505685119a\\\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/c8ef739a72ea5f7507a32fca52940befe437ac45\\\/2014\\\/07\\\/22\\\/36b8334d-1175-11e4-9732-00505685119a\\\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/","og_locale":"en_US","og_type":"article","og_title":"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-04-21T11:33:00+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/a\/img\/resize\/c8ef739a72ea5f7507a32fca52940befe437ac45\/2014\/07\/22\/36b8334d-1175-11e4-9732-00505685119a\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree","datePublished":"2022-04-21T11:33:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/"},"wordCount":746,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/c8ef739a72ea5f7507a32fca52940befe437ac45\/2014\/07\/22\/36b8334d-1175-11e4-9732-00505685119a\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/","url":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/","name":"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/c8ef739a72ea5f7507a32fca52940befe437ac45\/2014\/07\/22\/36b8334d-1175-11e4-9732-00505685119a\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp","datePublished":"2022-04-21T11:33:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/#primaryimage","url":"https:\/\/www.zdnet.com\/a\/img\/resize\/c8ef739a72ea5f7507a32fca52940befe437ac45\/2014\/07\/22\/36b8334d-1175-11e4-9732-00505685119a\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp","contentUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/c8ef739a72ea5f7507a32fca52940befe437ac45\/2014\/07\/22\/36b8334d-1175-11e4-9732-00505685119a\/charlie-osborne.jpg?width=50&amp;height=50&amp;fit=crop&amp;auto=webp"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/hive-hackers-are-exploiting-microsoft-exchange-servers-in-ransomware-spree\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Hive hackers are exploiting Microsoft Exchange Servers in ransomware spree"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/46334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=46334"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/46334\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=46334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=46334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=46334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}