> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
HUNTERS INTERNATIONAL
/actor/hunters-international/ · 0 intel reports
Hunters International is a ransomware and data theft extortion group that emerged in late 2023 following the FBI-led disruption of the Hive ransomware operation. Security researchers identified significant code overlaps between Hunters International's ransomware and the Hive ransomware source code, strongly suggesting that Hunters International either acquired the Hive source code after law enforcement seized Hive infrastructure, or represents a rebrand of former Hive operators continuing their criminal enterprise under a new identity.
Hunters International has publicly contested the Hive connection, claiming to have purchased the source code from a developer and operating as an independent entity. Regardless of the precise lineage, the group has demonstrated sophisticated ransomware capabilities and established its own data leak site where victim data is published following failed ransom negotiations.
The group has adopted a notably pragmatic approach to its criminal operations, explicitly stating in communications that their primary focus is data theft and extortion rather than ransomware deployment , reflecting an industry-wide recognition that file encryption is increasingly being used as a secondary mechanism rather than the primary value driver in extortion operations.
Hunters International has claimed victims across healthcare, manufacturing, education, and financial services sectors in North America, Europe, and Asia-Pacific, indicating a broad opportunistic targeting approach consistent with a RaaS model that relies on geographically diverse affiliates to source initial network access.
Tactical Telemetry and Extortion Framework: In confirmed intrusions, Hunters International employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.