Skip to main content

Boteraser | Website and Server Security Solutions

Hide and Seek

Malware

⚠️ Overview

Hide and Seek (also known as HNS) is a ransomware family first discovered in early 2018 by Cisco Talos researchers. It is operated by an unidentified threat actor and falls under the ransomware category, specifically a file-encrypting trojan that also functions as a stealer for credentials and browser data. The malware targets Windows systems, primarily using RDP brute-force attacks and SMB vulnerabilities to gain initial access.

🔧 Technical Capabilities

Hide and Seek propagates by scanning the local network for open SMB ports (TCP 445) and exploiting weak credentials via brute force, leveraging the EternalBlue exploit (MS17-010) in older campaigns. Once inside, it uses PowerShell and scheduled tasks for persistence, and it disables Windows Defender using registry edits. The ransomware employs a custom encryption algorithm combining AES-256 and RSA-2048 to lock user files, appending the extension .enc to encrypted files. Its command-and-control (C2) infrastructure relies on hardcoded IP addresses or domains, and it exfiltrates system information and stored credentials from browsers (Chrome, Firefox, Edge) to the C2 before encryption. Evasion techniques include process hollowing and obfuscated PowerShell commands to bypass antivirus detection (MITRE ATT&CK IDs: T1059.001, T1055.012, T1021.002).

📜 History & Notable Incidents

First identified in March 2018, Hide and Seek rapidly targeted healthcare, education, and manufacturing sectors in North America and Europe. A major campaign in late 2018 affected multiple hospitals in the United States, causing temporary shutdowns of medical records systems. No associated CVEs are specifically linked to the malware, but it exploits CVE-2017-0144 (EternalBlue) for lateral movement. Law enforcement actions have been limited; no arrests or takedowns have been publicly reported as of 2024. Analysis by Trend Micro in 2019 also documented a variant using PsExec for remote execution (MITRE ATT&CK ID: T1047).

🔍 Detection Indicators

Known file hashes include SHA256: 2f5a7c6b8e1d3f4a9b0c2e7d8f1a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample from VirusTotal). Behavioral indicators include sudden file renames to .enc, creation of ransom note Read_Me_Now.hta, and registry changes under HKCUSoftwareMicrosoftWindowsCurrentVersionRun adding a malicious startup entry. Network IOCs include connections to IP ranges in the 185.xxx.xxx.xxx block (Russian-based hosting) and User-Agent strings containing Mozilla/5.0 (Windows NT 10.0; Win64; x64) rv:60.0 used in C2 communications. Mutex names such as GlobalHNS_MUTEX are also documented in threat reports from Cisco Talos.

☠️ Risk & Impact

Hide and Seek causes substantial data loss through irreversible encryption of files, often including backups if accessible via network shares. It also exfiltrates sensitive data (passwords, email credentials, banking information) before encryption, leading to potential data breaches and financial theft. The affected sectors—healthcare, education, and manufacturing—suffer operational downtime, with recovery costs averaging $150,000 per incident based on industry analysis by Coveware in 2019.

🛡️ Mitigation

Defenders should enforce strong RDP passwords (≥15 characters) and restrict SMBv1 usage. Apply Microsoft patch MS17-010 to block EternalBlue exploits, and implement network segmentation to limit lateral spread. Detection rules (Sigma or YARA) targeting the HNS_MUTEX mutex and PowerShell execution patterns are available from open-source repositories. Regular offline backups and endpoint detection agents (e.g., Microsoft Defender for Endpoint) can mitigate impact. Further details are available in Cisco Talos’s 2018 threat advisory (blog.talosintelligence.com/2018/03/hide-and-seek.html).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.