🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
HUNTERS INTERNATIONAL

/actor/hunters-international/  ·  0 intel reports

Year Established
2023
Attribution
Unknown
Motivation
Financial
Modus Operandi (MO)
RaaS, data theft extortion, suspected Hive ransomware successor
Primary Aliases
Hunters

Hunters International is a ransomware and data theft extortion group that emerged in late 2023 following the FBI-led disruption of the Hive ransomware operation. Security researchers identified significant code overlaps between Hunters International's ransomware and the Hive ransomware source code, strongly suggesting that Hunters International either acquired the Hive source code after law enforcement seized Hive infrastructure, or represents a rebrand of former Hive operators continuing their criminal enterprise under a new identity.

Hunters International has publicly contested the Hive connection, claiming to have purchased the source code from a developer and operating as an independent entity. Regardless of the precise lineage, the group has demonstrated sophisticated ransomware capabilities and established its own data leak site where victim data is published following failed ransom negotiations.

The group has adopted a notably pragmatic approach to its criminal operations, explicitly stating in communications that their primary focus is data theft and extortion rather than ransomware deployment , reflecting an industry-wide recognition that file encryption is increasingly being used as a secondary mechanism rather than the primary value driver in extortion operations.

Hunters International has claimed victims across healthcare, manufacturing, education, and financial services sectors in North America, Europe, and Asia-Pacific, indicating a broad opportunistic targeting approach consistent with a RaaS model that relies on geographically diverse affiliates to source initial network access.

Tactical Telemetry and Extortion Framework: In confirmed intrusions, Hunters International employs double-extortion tactics, combining high-speed asymmetric encryption with automated data exfiltration pipelines. Initial access is routinely obtained via compromised Remote Desktop Protocol (RDP) credentials, initial access broker (IAB) marketplaces, and spear-phishing campaigns delivering infostealer payloads. Organizations operating critical IT infrastructure are advised to enforce strict network segmentation, deploy hardware-backed multi-factor authentication across all external access points, and maintain immutable offline backups to mitigate operational disruption.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles