World Leaks is a cyber extortion group that emerged in 2025 as a rebrand or spin-off of Hunters International, which itself has been described as linked historically to the Hive ransomware lineage. The group is associated with a shift away from traditional file encryption toward encryption-less extortion centered on data theft, rapid publication threats, and operation of a public leak site. Reporting consistently characterizes World Leaks as a data-theft and extortion operation, although some victim reporting and tracking still refer to it as a ransomware group. World Leaks has targeted organizations across multiple countries and sectors, with repeated victim claims involving the United States, India, Brazil, Italy, and other regions. Observed victims and claimed targets include healthcare providers and laboratories, manufacturers, educational institutions, business services firms, and contractors tied to critical infrastructure projects. Public reporting also links the group to incidents involving Nike, Tata Electronics, Reliance Infrastructure-related Kudankulam Nuclear Power Plant project data, Operation PAR, Centers Laboratory, and additional U.S.-based organizations. The group’s tradecraft is strongly associated with exfiltration and extortion rather than disruptive industrial control system activity. In the Kudankulam-related incident, World Leaks published a large cache of contractor data allegedly tied to conventional plant infrastructure and supplier documentation. In healthcare-related incidents, the group claimed theft of large volumes of personal, medical, and financial data and used leak-site publication as pressure when demands were not met. Reporting also notes the use of an in-house exfiltration tool called RustyRocket. World Leaks is part of the broader ransomware ecosystem trend toward data-theft-only extortion, lowering the technical barrier to operations while maintaining coercive leverage through public disclosure. The group has been observed maintaining a leak site, publishing stolen files after countdown deadlines expire, and in at least one reported case shortening the publication timeline. It has ranked among the more active extortion brands in 2026 and has been noted as focusing heavily on U.S.-based organizations while also conducting prominent operations in India and elsewhere. Known aliases include worldleaks, world_leaks, and Hunters International in the context of the rebrand lineage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2017-17215 9.1 NETGEAR Routers (R6400, R7000, R8000) World Leaks, TheGentlemen, Devman Link
Other cases include Oracle WebLogic Server CVE-2025-21535, a missing authentication vulnerability tied to initial access in activity attributed to Hunters International...
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of an emerging encryption-less, data theft-only extortion model rather than as a central actor in the report.
Claimed responsibility for breaching Operation PAR’s internal network, stealing confidential information, and threatening public release unless ransom demands were met.
Referenced as a ransomware and extortion group that published allegedly stolen files from contractors tied to India's largest nuclear power project and separately claimed an attack on Tata Electronics with a ransom demand.
Mentioned only as a comparison point for hosting large leaked datasets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.