Hunters Ransomware

Description Summary

In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold, along with its website and older versions developed in Golang and C (although this purchase has only been reported by the actors without concrete evidence). The buyer of this new source code was the group Hunters International, who claimed to have fixed the bugs in the Ransomware Hive that were responsible for preventing file decryption in some cases. The group also stated that file encryption would not be their primary focus; instead, they would use data theft as a method to pressure victims during extortion attempts.

Threat Actor

Hunters International — bought/repurposed the Hive source code after the FBI takedown; later dropped encryption for data-theft extortion.

Technical Indicators

Encryption Extension
.locked (Hive-derived)
Encryption Algorithm
Rust encryptor based on leaked Hive code; ChaCha20/RSA
Ransom Note Name
Contact Us.txt
Targeted Industries
Healthcare, Manufacturing, Technology
First Seen
October 2023
Last Seen
January 2025 (rebranded to World Leaks; shifted to pure data extortion)
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts