{"id":14391,"date":"2025-07-03T17:47:21","date_gmt":"2025-07-03T17:47:21","guid":{"rendered":"https:\/\/newestek.com\/?p=14391"},"modified":"2025-07-03T17:47:21","modified_gmt":"2025-07-03T17:47:21","slug":"hunters-international-shuts-ransomware-operations-reportedly-becomes-an-extortion-only-gang-called-world-leaks","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=14391","title":{"rendered":"Hunters International shuts ransomware operations, reportedly becomes an extortion-only gang called World Leaks"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p>Ransomware gang Hunters International says it\u2019s shutting down its operations for unexplained reasons, and is offering decryption keys to victim organizations.<\/p>\n<p>The offer of decryption keys could be good news for CISOs whose data were recently scrambled and who can\u2019t find a way to decrypt the files. However, judging from the history of ransomware gangs that have shut down before, Hunters International\u2019s members will likely reconstitute with the heart of their code and begin anew in one or more groups.<\/p>\n<p>\u201cWhether their offer [of free decryption keys] is true or not is anyone\u2019s guess at this point,\u201d threat analyst Luke Connolly of Emsisoft, who has seen the Hunters announcement, told CSO. \u201cKeep in mind that they are criminals, and ransomware groups are notorious for making false claims in support of their own objectives.\u201d<\/p>\n<p>According to a <a href=\"https:\/\/www.group-ib.com\/blog\/hunters-international-ransomware-group\/\" target=\"_blank\" rel=\"noreferrer noopener\">report by Singapore-based Group-IB<\/a>, Hunters International announced last November that it was shutting down due to government scrutiny and lowered profits, and has been renamed World Leaks.<\/p>\n<p>The report says that, unlike Hunters International, which combined data encryption with extortion, World Leaks operates as an extortion-only group using a custom-built data exfiltration tool. The World Leaks site today claims 31 victims whose data has been stolen.<\/p>\n<p>There is a growing trend towards extortion-only attacks, Group-IB adds. It addition, it says ransomware operators are also adopting stealthier techniques to avoid detection.<\/p>\n<p>Connolly isn\u2019t certain of a link to World Leaks from Hunters International, but a researcher at Sophos disagrees.<\/p>\n<p>\u201cHunters International has been responsible for listing almost 300 victims on their data leak site since they emerged in late 2023,\u201d commented Aiden Sinnott, senior threat researcher at Sophos. \u201cDespite their claim to shut down the Hunters International group, we believe it is likely that they have rebranded as World Leaks, a new group that does not deploy ransomware, but has conducted data theft and extortion attacks since January.\u201d<\/p>\n<p>Today\u2019s Hunters International statement tries to make the crooks look magnanimous. \u201cWe at Hunters International wish to inform you of a significant decision regarding our operations. After careful consideration and in light of recent developments we have decided to close the Hunters International project. The decision was not made lightly and we recognize the impact it has on the organizations we have interacted with.<\/p>\n<p>\u201cAs a gesture of goodwill and to assist those affected by our previous activities, we are offering free decryption software to all companies that have been impacted by our ransomware. Our goal is to ensure that you can recover your encrypted data without the burden of paying ransoms.\u201d\u00a0\u00a0\u00a0<\/p>\n<p>To access the decryption keys, victims are asked to go to the gang\u2019s official website.<\/p>\n<p>The closing of the Hunters International brand may be linked to governments forbidding, or demanding that victims report, ransom payments, as well as to increased pressure against ransomware-as-a-service gangs from police and cybersecurity companies in the past two years. Early in 2024, international law enforcement agencies <a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/lockbit-power-cut-four-new-arrests-and-financial-sanctions-against-affiliates\" target=\"_blank\" rel=\"noreferrer noopener\">arrested two members of the LockBit ransomware gang<\/a> and seized the group\u2019s web infrastructure. Then, in October, <a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/lockbit-power-cut-four-new-arrests-and-financial-sanctions-against-affiliates\" target=\"_blank\" rel=\"noreferrer noopener\">Europol announced<\/a> new arrests. Also last year, the FBI said it had <a href=\"https:\/\/www.fbi.gov\/contact-us\/field-offices\/cleveland\/news\/international-investigation-leads-to-shutdown-of-ransomware-group\" target=\"_blank\" rel=\"noreferrer noopener\">disrupted the Radar\/Dispossesor gang<\/a> and dismantled its servers in the US, the UK and Germany. In addition, a number of botnets that distribute ransomware and information stealers, such as those targeted in <a href=\"https:\/\/www.csoonline.com\/article\/2132427\/operation-endgame-deals-major-blow-to-malware-distribution-botnets.html\" target=\"_blank\">last year\u2019s Operation Endgame<\/a> against over 100 servers distributing malware, have been smashed or crippled.<\/p>\n<p>According to the Group-IB report, Hunters International emerged around October 2023, when the gang said it had purchased the source code of the Hive ransomware gang and fixed its flaws. It was known for mainly attacking real estate, healthcare, and professional services sectors. For some reason, according to Group-IB, Hunters International prohibited attacks on Israel, Turkey, the entire Far East, and the Russia-linked Commonwealth of Independent States (CIS) countries. However, the report adds, data leaks from companies in these regions suggest that these rules weren\u2019t strictly followed.\u00a0<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Ransomware gang Hunters International says it\u2019s shutting down its operations for unexplained reasons, and is offering decryption keys to victim organizations. The offer of decryption keys could be good news for CISOs whose data were recently scrambled and who can\u2019t find a way to decrypt the files. However, judging from the history of ransomware gangs that have shut down before, Hunters International\u2019s members will likely&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=14391\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-14391","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/14391","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14391"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/14391\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14391"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14391"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14391"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}