Group-IB reported that Hunters International, a ransomware group linked to data theft and extortion attacks, is winding down its criminal operation. The group said it would cease activity and provide victims with free decryptors, marking an unusual public shutdown for an active ransomware brand. The development follows the group’s involvement in multiple intrusions in which stolen data and encrypted systems were used to pressure organizations into paying.
The reported closure suggests a possible rebranding, fragmentation, or operational shift rather than a clean disappearance, a pattern seen repeatedly across the ransomware ecosystem. For defenders, the announcement may reduce immediate activity under the Hunters International name, but affiliates, tooling, and tactics tied to the group could persist under new banners, leaving organizations exposed to continued extortion and ransomware risk.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Group-IB published a blog post titled "The beginning of the end: the story of Hunters International," indicating public reporting and analysis of the ransomware group. No additional incident details are available in the provided reference content.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.