Hunters International was linked to two intrusion chains that show the ransomware group expanding beyond conventional Windows compromise into tailored access and virtualization-focused impact. Quorum Cyber identified a new RAT dubbed SharpRhino, assessed as related to the ThunderShell family, during a Hunters International ransomware incident in which the malware was allegedly delivered through a typosquatting site impersonating Angry IP Scanner. The RAT established persistence, enabled remote access, and used previously unseen methods to gain elevated privileges, while attribution to Hunters International was supported by observed tradecraft and the ransom note.
A separate Synacktiv investigation detailed a Hunters International attack that began with malvertising and a trojanized RVTools installer delivering the SMOKEDHAM backdoor, followed by deployment of Kickidler Grabber for surveillance and credential theft. The attackers used reverse SSH tunnels and RDP to pivot from an administrator workstation to internal servers, exfiltrated archived file shares with WinSCP, and then pushed a custom Rust-based ESXi encryptor via a PowerShell workflow using VMware PowerCLI to enable SSH, transfer the payload, and schedule execution on hypervisors. Synacktiv said the malware targeted files under /vmfs/volumes, powered off virtual machines, encrypted data with AES-256-CTR, appended RSA-encrypted metadata, and could also consume free disk space with random data.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Synacktiv investigated a compromise involving a Hunters International ESXi ransomware variant that appeared after summer 2024. The case documented a full intrusion chain from initial access to ESXi encryption.
Multiple sources reported code overlap between Hunters International ransomware samples and Hive samples. Hunters International also said it had acquired Hive's source code while denying it was Hive's successor.
A joint Europol and FBI operation seized and shut down the Hive ransomware group's RaaS infrastructure. The report notes that no arrests were made in the takedown.
Quorum Cyber reported a new Remote Access Trojan named SharpRhino during a ransomware incident it attributed to Hunters International. The company assessed this was likely the first publicly reported deployment of SharpRhino by the group.
The day after the data exfiltration, the attackers started deploying ransomware against the victim's VMware infrastructure from CRITICAL_SERVER. Synacktiv's report says the operation used a custom ESXi encryptor delivered through PowerShell, VMware PowerCLI, and WinSCP Automation.
Two weeks after moving to CRITICAL_SERVER, the attackers accessed the company file server via RDP, installed Total Commander, and used its 7zip plugin to archive most file shares. They then used WinSCP Portable and a PuTTY private key to exfiltrate the archives to a remote server, likely over SFTP.
Using the local Administrator account over RDP, the attackers accessed CRITICAL_SERVER and installed SMOKEDHAM with a Run key named UpdateWindowsKey. They later added Kitty, Grabber, and Splashtop Remote Service to maintain access and continue lateral movement.
Weeks later, the attackers used Kitty, renamed fork.exe, to create a reverse SSH tunnel from the administrator workstation to an attacker-controlled AWS EC2 instance. The tunnel enabled RDP access to internal servers not exposed to the Internet.
Minutes after SMOKEDHAM was installed, the attackers deployed Kickidler Grabber using grem.msi on the administrator workstation. Grabber created a persistent Windows service named ngs running as LocalSystem.
The intrusion began when a system administrator downloaded RVTools from a malicious website promoted through malvertising. The trojanized installer executed the legitimate MSI while deploying malicious files and persistence for the SMOKEDHAM backdoor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.