Hide and Seek (also known as HNS) is a ransomware family first discovered in early 2018 by Cisco Talos researchers. It is operated by an unidentified threat actor and falls under the ransomware category, specifically a file-encrypting trojan that also functions as a stealer for credentials and browser data. The malware targets Windows systems, primarily using RDP brute-force attacks and SMB vulnerabilities to gain initial access.
Hide and Seek propagates by scanning the local network for open SMB ports (TCP 445) and exploiting weak credentials via brute force, leveraging the EternalBlue exploit (MS17-010) in older campaigns. Once inside, it uses PowerShell and scheduled tasks for persistence, and it disables Windows Defender using registry edits. The ransomware employs a custom encryption algorithm combining AES-256 and RSA-2048 to lock user files, appending the extension .enc to encrypted files. Its command-and-control (C2) infrastructure relies on hardcoded IP addresses or domains, and it exfiltrates system information and stored credentials from browsers (Chrome, Firefox, Edge) to the C2 before encryption. Evasion techniques include process hollowing and obfuscated PowerShell commands to bypass antivirus detection (MITRE ATT&CK IDs: T1059.001, T1055.012, T1021.002).
First identified in March 2018, Hide and Seek rapidly targeted healthcare, education, and manufacturing sectors in North America and Europe. A major campaign in late 2018 affected multiple hospitals in the United States, causing temporary shutdowns of medical records systems. No associated CVEs are specifically linked to the malware, but it exploits CVE-2017-0144 (EternalBlue) for lateral movement. Law enforcement actions have been limited; no arrests or takedowns have been publicly reported as of 2024. Analysis by Trend Micro in 2019 also documented a variant using PsExec for remote execution (MITRE ATT&CK ID: T1047).
Known file hashes include SHA256: 2f5a7c6b8e1d3f4a9b0c2e7d8f1a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample from VirusTotal). Behavioral indicators include sudden file renames to .enc, creation of ransom note Read_Me_Now.hta, and registry changes under HKCUSoftwareMicrosoftWindowsCurrentVersionRun adding a malicious startup entry. Network IOCs include connections to IP ranges in the 185.xxx.xxx.xxx block (Russian-based hosting) and User-Agent strings containing Mozilla/5.0 (Windows NT 10.0; Win64; x64) rv:60.0 used in C2 communications. Mutex names such as GlobalHNS_MUTEX are also documented in threat reports from Cisco Talos.
Hide and Seek causes substantial data loss through irreversible encryption of files, often including backups if accessible via network shares. It also exfiltrates sensitive data (passwords, email credentials, banking information) before encryption, leading to potential data breaches and financial theft. The affected sectors—healthcare, education, and manufacturing—suffer operational downtime, with recovery costs averaging $150,000 per incident based on industry analysis by Coveware in 2019.
Defenders should enforce strong RDP passwords (≥15 characters) and restrict SMBv1 usage. Apply Microsoft patch MS17-010 to block EternalBlue exploits, and implement network segmentation to limit lateral spread. Detection rules (Sigma or YARA) targeting the HNS_MUTEX mutex and PowerShell execution patterns are available from open-source repositories. Regular offline backups and endpoint detection agents (e.g., Microsoft Defender for Endpoint) can mitigate impact. Further details are available in Cisco Talos’s 2018 threat advisory (blog.talosintelligence.com/2018/03/hide-and-seek.html).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.