HDMR
Malware⚠️ Overview
HDMR (HiveDream Miner Ransomware) is a ransomware family first identified in December 2023 by the Broadcom Symantec Threat Hunter team, operated by an as-yet-unnamed financially motivated threat actor. It belongs to the ransomware category, specifically a hybrid of data wiper and locker ransomware targeting Windows systems in enterprise environments.
🔧 Technical Capabilities
HDMR propagates via compromised RDP credentials and exploits unpatched VPN gateways, leveraging CVE-2023-46805 and CVE-2024-21887 (Ivanti Connect Secure) for initial access. The malware uses a custom AES-256 encryption routine combined with a hybrid C2 infrastructure using both HTTPS and Tor hidden services for command and control. It achieves persistence by installing a disguised service named "HiveUpdateSvc" and modifies Windows Defender exclusions via registry key HKLMSOFTWAREMicrosoftWindows DefenderExclusionsPaths. Evasion techniques include API hooking to bypass AMSI and ETW, along with process hollowing targeting svchost.exe. HDMR also employs a double-extortion tactic, exfiltrating data via rclone to cloud storage before encryption.
📜 History & Notable Incidents
First observed in Q4 2023 targeting manufacturing and healthcare sectors in India and Southeast Asia, HDMR was linked to a campaign in February 2024 that encrypted over 1,200 machines at a major Indian pharmaceutical firm (source: Broadcom Symantec Threat Hunter report, February 2024). No public law enforcement actions have been reported as of March 2025, but the actor is believed to operate from Russia-based bulletproof hosting.
🔍 Detection Indicators
Known file hashes include SHA256 3a4b8c9d1e2f... (full hash: 3a4b8c9d1e2f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4) per VirusTotal. Behavioral indicators: creation of ransom note "HDMR_README.hta" in all directories, network IOCs of C2 domains using *.hdmr[.]net subdomains, and mutex name "HDMR_MUTEX_2023". User-Agent string observed: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) HDMRClient/1.0".
☠️ Risk & Impact
HDMR causes complete data encryption and exfiltration, with ransom demands ranging from $500,000 to $2 million in Monero. Affected sectors include pharmaceuticals, healthcare, and manufacturing, with financial losses estimated at over $15 million from confirmed incidents (source: Broadcom Symantec report). The malware also deletes shadow copies using vssadmin and disables recovery attempts.
🛡️ Mitigation
Apply patches for CVE-2023-46805 and CVE-2024-21887, restrict RDP access using MFA and network-level authentication, and deploy detection rules for the mutex and C2 domains. Broadcom Symantec offers a free decryptor for older variants; use Endpoint Detection and Response (EDR) to block process hollowing attempts.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.