WorldLeaks
WorldLeaks is a ransomware threat group/malware name referenced as part of ransomware alliances active in 2025. The provided content places WorldLeaks alongside Qilin and SafePay as central to alliances targeting business services, manufacturing, and healthcare. The context identifies it within broader ransomware activity characterized by extortion operations and collaboration among groups, but does not provide specific technical details on WorldLeaks’ malware functionality, infection chain, payload behavior, or indicators of compromise. Based on the available content, the high-confidence assessment is that WorldLeaks is associated with ransomware operations targeting business services, manufacturing, and healthcare sectors as part of cooperative criminal alliances.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Collection
1 technique
Collection
Exfiltration
1 technique
Exfiltration
WorldLeaks is an extortion-focused cybercrime group that steals company data to pressure victims into paying, threatening public leaks if they refuse. The group emerged in 2025 after rebranding from Hunters International. Following increased law-enforcement pressure, it abandoned file encryption and shifted entirely to data theft and extortion.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WorldLeaks is a ransomware group involved in alliances targeting business services, manufacturing, and healthcare industries.
WorldLeaks is a ransomware group participating in alliances with other ransomware actors, focusing on industries such as business services, manufacturing, and healthcare.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.