World Leaks is a cyber extortion and ransomware-branded threat actor that emerged in 2025 as a rebrand or spin-off of Hunters International. It is widely characterized as having shifted emphasis from traditional file encryption toward data theft and extortion, using a leak site to pressure victims by publishing stolen information when demands are not met. Reporting also links Hunters International historically to the Hive lineage, although World Leaks is primarily tracked as a distinct post-Hunters operation. The group has claimed intrusions across multiple countries and sectors, with repeated victim reporting involving the United States and India. Observed victims and claimed targets include healthcare providers and laboratory services, manufacturers, education organizations, business services, and contractors tied to critical infrastructure projects. Publicly reported incidents include attacks or extortion claims involving Operation PAR, Centers Laboratory, Nike, Tata Electronics, Reliance Infrastructure-related Kudankulam Nuclear Power Plant project data, and additional organizations in the United States, Brazil, Canada, and Italy. World Leaks is associated with large-scale data exfiltration and leak-site publication of stolen records, including sensitive personal, medical, financial, engineering, supplier, and corporate information. In several cases, the actor publicly named victims on its leak site, threatened release of stolen data, and then published material after nonpayment. The group has been described as capable of hosting and releasing very large datasets and, in at least some reporting, using short publication deadlines to intensify extortion pressure. Capabilities directly associated with World Leaks include initial access, data exfiltration, post-exploitation activity, persistence in victim environments, and extortion through public disclosure. Reporting on the group also references use of an in-house exfiltration utility known as RustyRocket. The actor’s operational pattern is consistent with financially motivated cybercrime centered on theft of data and coercive monetization rather than espionage or destructive objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2017-17215 9.1 NETGEAR Routers (R6400, R7000, R8000) World Leaks, TheGentlemen, Devman Link
Other cases include Oracle WebLogic Server CVE-2025-21535, a missing authentication vulnerability tied to initial access in activity attributed to Hunters International...
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for breaching Operation PAR’s internal network, stealing confidential information, and threatening public release unless ransom demands were met.
Referenced as a ransomware and extortion group that published allegedly stolen files from contractors tied to India's largest nuclear power project and separately claimed an attack on Tata Electronics with a ransom demand.
Mentioned only as a comparison point for hosting large leaked datasets.
Conducting a ransomware attack against PinnPACK, a US-based manufacturing organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.