Hunters International

First seen
2023-07-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-16 17:56:14
Profile updated
2026-07-07 15:06:13

Targeted industries: healthcare-and-pharmaceutical financial-services professional-services

Context

Emerging in Q3 2023 as a Ransomware-as-a-Service (RaaS) operation, Hunters International has established itself as a distinct yet controversial threat actor in the cybercrime ecosystem. While initial analysis revealed a code overlap with the dismantled Hive ransomware, the group claims independence, asserting it purchased Hive’s source code rather than directly rebranding. This operational lineage enables advanced double-extortion campaigns prioritizing data exfiltration over encryption, with confirmed theft of medical records, financial data, and proprietary business information. The group's ransomware is written in Rust, a programming language favored for its resilience to reverse engineering and cross-platform compatibility.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Hunters International (report)
  • Trend Micro — Ransomware Spotlight Water Ouroboros (report)
  • x.com — 1715345562034225621 (report)

External references