Hunters International
- First seen
- 2023-07-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-16 17:56:14
- Profile updated
- 2026-07-07 15:06:13
Targeted industries: healthcare-and-pharmaceutical financial-services professional-services
Context
Emerging in Q3 2023 as a Ransomware-as-a-Service (RaaS) operation, Hunters International has established itself as a distinct yet controversial threat actor in the cybercrime ecosystem. While initial analysis revealed a code overlap with the dismantled Hive ransomware, the group claims independence, asserting it purchased Hive’s source code rather than directly rebranding. This operational lineage enables advanced double-extortion campaigns prioritizing data exfiltration over encryption, with confirmed theft of medical records, financial data, and proprietary business information. The group's ransomware is written in Rust, a programming language favored for its resilience to reverse engineering and cross-platform compatibility.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Hunters International (report)
- Trend Micro — Ransomware Spotlight Water Ouroboros (report)
- x.com — 1715345562034225621 (report)