◇ SIGN IN
← all actors
ransomware

Hunters International

defunctmedium confidence
Ransomware
Hunters IntlWorld Leaks (successor)
Attribution
RaaS (successor to Hive tooling; rebranded to extortion-only World Leaks)
Origin
Unknown
First seen
2023
Last active
2025
Motivation
Financially motivated (ransomware / data extortion)
Confidence
medium
MENA targeting
UAE, Tunisia
Sectors
Technology, unspecified Tunisia sector

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting UAE, Tunisia (Technology, unspecified Tunisia sector sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Hunters International was a ransomware-as-a-service group launched in late 2023 whose encryptor showed heavy code overlap with the disrupted Hive ransomware; in 2025 it wound down the ransomware brand and rebranded to the extortion-only 'World Leaks.'

History

Hunters International appeared in late 2023 and was quickly assessed by researchers to reuse code substantially overlapping with Hive, which had been disrupted by law enforcement in January 2023; the group denied being a direct Hive successor and characterized itself as having acquired the encryptor. It operated a RaaS affiliate model and, per aggregated tracking, was linked to dozens of confirmed and many more unconfirmed attacks, with a notable share of impact in healthcare.

In 2025 the operation pivoted away from encryption toward pure data-theft extortion. Group-IB reported in April 2025 that Hunters International was rebranding to 'World Leaks,' an extortion-only operation launched at the start of 2025; the group subsequently announced the shutdown of the Hunters International brand effective around July 2025 and offered free decryptors to prior victims. World Leaks continued data-extortion activity against targets in Europe and the US.

Hunters International's claimed victimology was global; MENA-relevant claims include the UAE and Tunisia. Because these derive from leak-site postings, they should be treated as unverified claims unless confirmed by a reputable source or the affected organization. The Hunters International brand itself is assessed defunct, with activity continuing under the World Leaks successor.

Notable campaigns

2024
Global RaaS extortion campaign
Dozens of confirmed victims across sectors, with heavy healthcare impact (claims aggregated by trackers).
2025
Rebrand to World Leaks
Shifted to extortion-only World Leaks and wound down the Hunters International brand, offering free decryptors.

Claimed victims · 307 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
Wrap & Send ServicesUSRetail & E-Commerce
CorantioquiaCOGovernment & Defense
Eight8Ate Holdings, IncPHRetail & E-Commerce
Sioux ChiefUSManufacturing
GPF LewisGBProfessional Services
Telco IntercontinentalUSTechnology
FCCESGovernment & Defense
Digestive SpecialistsUSHealthcare
Minnesota Lawyers Mutual InsuranceUSFinancial Services
Kenworth Del SurMXTransportation
Kasb Bank - K-TradePKFinancial Services
MafiATOther