World Leaks is a financially motivated ransomware and data-extortion operation that emerged in 2025 as the successor or rebranding of Hunters International, a ransomware-as-a-service operation widely linked to the post-disruption Hive ecosystem. Hunters International ceased operations in July 2025, while World Leaks continued operations under an extortion-focused model. The group primarily uses theft and threatened publication of victim data through a dedicated leak site, including encryption-less extortion, rather than relying solely on ransomware encryption. World Leaks has claimed victims across multiple sectors, including healthcare, manufacturing, education, and utility-related infrastructure. Reported activity includes publication or threatened publication of allegedly stolen corporate, personal, technical, financial, and engineering material. The operation has targeted organizations in the United States and India, including healthcare providers and entities connected to critical-infrastructure projects. Hunters International activity associated with the lineage used Rclone and WinSCP for data exfiltration, RDP for lateral movement, reverse SSH tunneling, credential collection, remote-access malware, defense evasion, and ransomware deployment against VMware ESXi environments. Victim claims and leak-site postings should be treated as extortion claims unless independently corroborated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2017-17215 9.1 NETGEAR Routers (R6400, R7000, R8000) World Leaks, TheGentlemen, Devman Link
Other cases include Oracle WebLogic Server CVE-2025-21535, a missing authentication vulnerability tied to initial access in activity attributed to Hunters International...
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Defunct RaaS operation and suspected Hive rebrand that transitioned elements of its operation to World Leaks.
A ransomware/data leak group listed among the top groups by number of incidents.
Referenced as an example of an emerging encryption-less, data theft-only extortion model rather than as a central actor in the report.
Claimed responsibility for breaching Operation PAR’s internal network, stealing confidential information, and threatening public release unless ransom demands were met.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.