Hive0065 is an advanced persistent threat (APT) that has been identified by security researchers. It is also referred to as "Operation Erebus" and was first discovered in 2018. The APT targets government organizations, defense contractors, aerospace companies, telecommunications firms, energy sector entities, and other high-profile industries. Hive0065 has been linked to several countries including China, Russia, Iran, North Korea, and the United States. It is believed that this APT group may have ties with Chinese military intelligence or the People's Liberation Army (PLA). The group uses a variety of tactics such as spear-phishing emails, watering hole attacks, and exploiting vulnerabilities in software to gain access to their targets. Hive0065 is considered one of the most sophisticated APT groups due to its advanced techniques and persistent nature.
Techniques, tactics and practices:
Hive0065 is a highly sophisticated advanced persistent threat that employs various techniques to gain access to its targets. Some of these tactics include spear-phishing emails, watering hole attacks, and exploiting vulnerabilities in software. The group also uses stealthy methods such as avoiding detection by using multiple layers of encryption or hiding their activities within legitimate network traffic. Hive0065 is known to be persistent, meaning that they continue to attack even after being detected, making it difficult for organizations to fully eliminate the threat. Additionally, the group has been linked to several countries including China, Russia, Iran, North Korea, and the United States, indicating a high level of coordination between different APT groups.
