Hunters International is a ransomware-as-a-service operation that emerged in late 2023 and is widely assessed as a technical successor or rebrand of Hive, based on code similarities and operational lineage, although the operators have publicly denied direct continuity. The group has targeted organizations across multiple sectors and geographies, including healthcare, government-related entities, construction, manufacturing, and other commercial enterprises, and has been associated with both file-encrypting ransomware attacks and data-theft extortion.
The operation initially followed a conventional double-extortion model, combining network intrusion, data exfiltration, and file encryption with publication threats on a leak site. Victim reporting and intrusion clustering tie the group to extortion activity against large organizations and to campaigns in which stolen data was used to pressure not only the breached entity but also affected individuals. Hunters International has also been linked to activity clusters involving credential dumping from directory services and use of proxying and exfiltration infrastructure during post-compromise operations.
By late 2024, Hunters International increasingly emphasized exfiltration-only extortion, reflecting a broader shift in the ransomware ecosystem away from encryption-centric operations. In 2025, the group was assessed to have rebranded toward the World Leaks data-extortion model and to have provided affiliates with a custom exfiltration capability. Reporting also indicates that the operation later announced a shutdown and promised free decryption keys for prior victims, though its broader ecosystem and successor branding continued to appear in extortion activity.
Hunters International has been used by financially motivated affiliates and intrusion sets, including Storm-0501, which has deployed multiple ransomware families across on-premises and hybrid-cloud environments. In those broader affiliate contexts, access has been associated with weak or stolen credentials, exploitation of remote access and public-facing vulnerabilities, credential theft, lateral movement, and cloud-focused post-exploitation. The malware is part of the modern RaaS ecosystem in which operators supply ransomware and extortion infrastructure while affiliates conduct intrusions against victim networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Fortinet FortiOS CVE-2024-55591, a zero-day authentication bypass vulnerability disclosed in January 2025, had the highest count of ransomware groups attached to it as the year closed, with six named ransomware families (DragonForce, Hunters International, NightSpire, Qilin, RansomHub, and SuperBlack)...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, a U.S.-based commercial construction contractor allegedly breached in early June 2025 had previously been victimized by GOLD CRESCENT’s Hunters International ransomware in October 2024 and by Payout Kings in June 2025.
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
1 distinct technique documented for this family, organized by ATT&CK tactic.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Former ransomware group described as the predecessor/spin-off origin for WorldLeaks. The article notes it exited and offered free decryption keys in July 2025.
Ransomware family deployed by Storm-0501 in campaigns targeting hybrid cloud and on-premises environments.
Hunters International is referenced as a separate ransomware operation that had previously victimized one of the same organizations later listed by GOLD SALEM.
A ransomware family/group referenced in a case where a victim first received a LockBit-branded extortion note and later a Hunters International ransom demand, suggesting possible affiliate crossover or reuse of access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.