WorldLeaks is a ransomware and data-extortion operation that emerged in 2025 and has been described as a spin-off of Hunters International, which itself has been linked historically to the Hive ransomware lineage. The group is associated with double-extortion activity in which data is stolen from victims and then used for coercion through leak-site publication deadlines and public exposure. Reported victimology spans multiple countries, with notable concentration in the United States and the United Kingdom, and sector targeting has prominently included healthcare, manufacturing, and business services.
WorldLeaks has been tied to large-scale data theft incidents and operation of a data leak site used to announce victims and publish stolen material. In at least one reported case, the group shortened its publication deadline from a previously observed seven-day window to roughly two days, indicating an aggressive extortion tempo. The operation has also been associated with RustyRocket, an in-house exfiltration tool reportedly built for both Windows and Linux, reinforcing the assessment that data theft is a core component of its tradecraft.
Reporting also places WorldLeaks among ransomware-group alliances that share tactics or cooperate operationally with other extortion actors. The group has been characterized as capable of handling large stolen datasets and participating in broader collaborative ecosystems targeting enterprise organizations. High-confidence reporting supports its role as a ransomware-led extortion actor rather than a purely opportunistic leak brand.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
WorldLeaks is an extortion-focused cybercrime group that steals company data to pressure victims into paying, threatening public leaks if they refuse. The group emerged in 2025 after rebranding from Hunters International. Following increased law-enforcement pressure, it abandoned file encryption and shifted entirely to data theft and extortion.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point for large-file hosting capability of leak infrastructure.
Ransomware/extortion group described as a spin-off of Hunters International, focused heavily on data theft and leak-site extortion. The article says it leaked Reliance Infrastructure data and used an in-house exfiltration tool called RustyRocket. It reportedly gives victims a short negotiation window before publishing stolen data.
WorldLeaks is a ransomware group involved in alliances targeting business services, manufacturing, and healthcare industries.
WorldLeaks is a ransomware group participating in alliances with other ransomware actors, focusing on industries such as business services, manufacturing, and healthcare.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.