Description Summary
In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold, along with its website and older versions developed in Golang and C (although this purchase has only been reported by the actors without concrete evidence). The buyer of this new source code was the group Hunters International, who claimed to have fixed the bugs in the Ransomware Hive that were responsible for preventing file decryption in some cases. The group also stated that file encryption would not be their primary focus; instead, they would use data theft as a method to pressure victims during extortion attempts.
Threat Actor
Hunters International — bought/repurposed the Hive source code after the FBI takedown; later dropped encryption for data-theft extortion.
Technical Indicators
.locked (Hive-derived)
Rust encryptor based on leaked Hive code; ChaCha20/RSA
Contact Us.txt
Healthcare, Manufacturing, Technology
October 2023
January 2025 (rebranded to World Leaks; shifted to pure data extortion)
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |