World Leaks is an affiliate-based extortion operation and successor to Hunters International. It primarily employs data theft, leak-site publication threats, victim negotiations, and resale or exposure of stolen information rather than relying solely on file encryption. The operation provides affiliates with proprietary data-exfiltration tooling and operates infrastructure supporting leak publication, negotiations, affiliate administration, and insider recruitment. World Leaks has targeted organizations globally, particularly in the United States, Canada, and Europe, including healthcare, manufacturing, and technology organizations.
Reported intrusion activity includes access through exposed or compromised VPN infrastructure, valid credentials, phishing, Remote Desktop Protocol, and public-facing applications. Affiliates have conducted internal reconnaissance and network scanning; used remote administration and native management mechanisms for lateral movement; established persistence through scheduled tasks, account changes, and system-configuration modifications; and exfiltrated data using command-line transfer tooling and cloud-storage services. Although World Leaks has positioned itself as an encryption-free extortion service, a healthcare-sector intrusion identified in 2026 involved both data exfiltration and ransomware encryption, indicating that affiliate activity can include conventional ransomware deployment in addition to extortion-only operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
World Leaks emerged in early 2024 as a direct rebrand of the Hunters International ransomware group... In January 2026, Darktrace identified the presence of ransomware and data encryption linked to World Leaks within the network of an organization within the healthcare sector.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An active encryption-free extortion successor operation connected to Hunters International.
An extortion-focused ransomware brand exemplifying encryption-less, data theft-only operations where leverage comes from publication rather than file encryption.
RaaS operation, described as a rebrand of Hunters International, that used basic searchable data-leak-site interfaces for indexing stolen data by category and keyword.
An emerging or returning ransomware group identified in Halcyon’s Q2 2026 reporting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.