Cybercrime

Two People Arrested in Australia and US for Development and Sale of Hive RAT

Authorities in Australia and the US have arrested and charged two individuals for developing and selling the Hive RAT.

Authorities in Australia and the US have arrested and charged two individuals for developing and selling the Hive RAT.

Authorities in Australia and the US have announced the arrest and indictment of two individuals for their roles in the development and sale of the Hive remote access trojan (RAT).

Initially developed and distributed under the name of Firebird, the malware was marketed as a remote access tool that could stay hidden and steal sensitive information from the targeted systems.

Last week, law enforcement in Australia announced the arrest of an individual allegedly involved in the development of Firebird and its sale through a hacking forum.

The man was charged with twelve counts of computer offenses and is scheduled to appear in court on May 7, the Australian authorities said.

Simultaneously, the US Department of Justice (DoJ) announced the arrest of and charges against Edmond Chakhmakhchyan, a 24 year-old resident of Van Nuys, San Fernando Valley, for selling the Hive RAT on a hacker forum.

According to the indictment, Chakhmakhchyan, who used the online moniker of ‘Corruption’, was involved in advertising and selling the RAT, and also provided paying customers with assistance.

Advertisement. Scroll to continue reading.

The malware provided users with unauthorized access to the infected systems, allowing them to close or disable applications, steal login information for bank accounts and cryptocurrency wallets, browse data on the system, log keystrokes, and eavesdrop on the victim’s communications.

According to the indictment, Chakhmakhchyan started working with the Firebird/Hive RAT author in 2020 and at one point sold the malware to “an undercover employee of a law enforcement agency”.

Evidence collected by investigators allegedly shows that Chakhmakhchyan was aware that the RAT would be used by customers to conduct illegal activities, such as stealing cryptocurrency.

Chakhmakhchyan appeared in court last week and pleaded not guilty. He is scheduled for trial on June 4.

Related: Two More Individuals Charged for DraftKings Hacking

Related: Nigerian Arrested, Charged in $7.5 Million BEC Scheme Targeting US Charities

Related: Canadian Man Sentenced to Prison for Ransomware Attacks

Related: Warzone RAT Shut Down by Law Enforcement, Two Arrested

Related Content

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Cybercrime

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.

Cybercrime

The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.

Cybercrime

Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.

Cybercrime

The 13-country effort, named Operation Ramz, targeted cyber threats in the Middle East and North Africa region.

Mobile & Wireless

Offered as a MaaS to a small number of affiliates, mainly Russian speakers, the RAT can turn devices into residential proxy nodes.

Malware & Threats

The malware mimics the legitimate Anthropic installation, relies on DLL sideloading, and cleans up after itself.

Malware & Threats

The malware can spy on victims, steal their information, and make configuration changes on devices.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version