Hunters International was a ransomware-as-a-service operation active from late 2023 until its reported shutdown on July 4, 2025. It was widely assessed as a likely successor or rebrand of Hive because of code overlap between their encryptors; the operators stated that they had acquired Hive source code but denied being Hive’s direct successor. The operation conducted double-extortion campaigns, stealing data before encrypting systems, and by late 2024 had shifted substantial activity toward exfiltration-only extortion. World Leaks has been assessed as a successor or rebrand associated with the operation.
Hunters International affiliates targeted organizations across multiple sectors, including healthcare, construction, government-related organizations, and critical infrastructure. Observed intrusions used malvertising to distribute trojanized administrative software, leading to deployment of a remote-access backdoor and prolonged credential collection and surveillance. Affiliates used reverse SSH tunnels, RDP, and remote-access tooling for internal access, archived network-share data for exfiltration, and disabled endpoint protection before ransomware deployment.
A VMware ESXi-focused Hunters International encryptor is a stripped Rust ELF executable. It targets VMware virtual-machine files, can stop running virtual machines, encrypts data using AES-256 in CTR mode with RSA-protected metadata, supports delayed execution and multithreaded operation, and can overwrite available disk space with random data. Deployment against virtual infrastructure has been observed through VMware management automation and SSH-based transfer and execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Fortinet FortiOS CVE-2024-55591, a zero-day authentication bypass vulnerability disclosed in January 2025, had the highest count of ransomware groups attached to it as the year closed, with six named ransomware families (DragonForce, Hunters International, NightSpire, Qilin, RansomHub, and SuperBlack)...
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le CSIRT de Synacktiv a observé une compromission impliquant un ransomware ESXi de Hunters International, une nouvelle variante apparue après l'été 2024.
For example, a U.S.-based commercial construction contractor allegedly breached in early June 2025 had previously been victimized by GOLD CRESCENT’s Hunters International ransomware in October 2024 and by Payout Kings in June 2025.
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
1 distinct technique documented for this family, organized by ATT&CK tactic.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A now-shuttered RaaS operation suspected to be a Hive rebrand. Its operations transitioned in part to the encryption-free World Leaks extortion brand.
Former ransomware group described as the predecessor/spin-off origin for WorldLeaks. The article notes it exited and offered free decryption keys in July 2025.
Ransomware associated in this content with RDP-based lateral movement.
Ransomware family deployed by Storm-0501 in campaigns targeting hybrid cloud and on-premises environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.