Home/Threat Actor/Hunters International
Threat Actor

Hunters International

hunters_international · ransomware_raas_hive_lineage_disputed_rebrand · active since 2023-10

Hunters International (canonical naming) is a Rust- based Ransomware-as-a-Service (RaaS) operation emerging October 20, 2023 following FBI Hive takedown January 2023, with cluster-defining 60% code overlap with Hive ransomware confirming Hive lineage per @rivitna2 + @BushidoToken canonical October 20, 2023 detection while operators publicly disputing rebrand characterization stating they acquired source code + infrastructure from former Hive operators as independent group ("In an uncommon statement, which is the sole communication from the group thus far, Hunters International addressed these speculations. They declared that, rather than being a rebranded iteration of Hive, they are an independent ransomware group that acquired the source code and infrastructure from Hive. Hunters International claimed to have a primary focus on data exfiltration rather than data encryption")

independent RaaS with Hive lineage attribution via Bitdefender November 2023 canonical analysis + Acronis 2024 + Barracuda + Quorum Cyber SharpRhino disclosure + SOCRadar Dark Web Profile + Picus Security + Forescout + Blackpoint + Daily Security Review industry coverage + Russian-hosting + Mihail Kolesnikov fake-identity NiceNIC domain service registration signature shared with Rilide Infostealer + Snatch ransomware phishing domains; standalone cluster paralleling embargo + cactus + trigona in v0.1.160 2022-2025 post-takedown + emerging RaaS cell.

operational target profile 200+ confirmed victims with 134 attacks first 7 months of 2024 + 10th most active 2024 ransomware group per Quorum Cyber + signature high-profile victims including U.S. Marshals + FBI data leaks + ICBC London Branch September 2024 (5.2 million files + 6.6 TB stolen per Picus Security) + Schneider Electric January 2024 + Anderson Oil & Gas November 2024 + Barber Specialties January 2025 + multi-sector across healthcare + automotive + manufacturing + logistics + finance + education + food + oil/gas + industrial across United States + United Kingdom + Germany + Japan + Brazil with Russia explicitly avoided per signature operational principle.

July 4, 2025 official shutdown with 55 confirmed + 199 unconfirmed attacks total per SOCRadar marking ~21-month operational lifecycle; operational attack architecture: (1) cluster- defining 60% Hive ransomware source code overlap per @rivitna2 + @BushidoToken October 20, 2023 detection establishing Hive lineage.

(2) cluster- defining Rust-based encryptor rewrite from Hive's earlier C + Golang variants for detection evasion + parallelism + cross-platform compatibility per Bitdefender ("Rust is gaining favor among ransomware operators, with another notable example being BlackCat, due to its relative resilience to reverse engineering by security researchers, robust control over low-level resources, excellent support for parallelism crucial for swift file encryption, and a wide array of cryptographic libraries")

(3) cluster-defining data-exfiltration-top-priority innovation over Hive encryption-first approach per Bitdefender ("the group's focus significantly leans towards stealing data, as evidenced by all known victims experiencing data exfiltration, whereas not every victim's data was encrypted"); (4) cluster-defining SharpRhino custom backdoor with AngryIP Scanner legitimate-tool masquerade + NSIS (Nullsoft Scriptable Install System) packing per Quorum Cyber 2024 disclosure.

(5) cluster- defining MEGA cloud storage data exfiltration tradecraft per Forescout Oracle WebLogic investigation.

(6) signature embedded-encryption- keys-within-encrypted-files Rust tradecraft complicating decryption analysis while streamlining paying-victim recovery.

(7) cluster-defining Mihail Kolesnikov fake-identity NiceNIC domain service registration signature with 400+ domains shared with Rilide Infostealer + Snatch ransomware phishing per SOCRadar + Blackpoint with huntersinternational.org legitimate-2017-2021- domain reactivated January 2024 for surface-web leak site.

(8) cluster-defining buffer.swp free- space wipe technique with 16,384 bytes random data continuously written until disk full preventing recovery.

(9) cluster-defining November 2024 farewell letter exit announcement then weeks-later return per Blackpoint signature exit-then-resume tradecraft.

(10) cluster-defining late-2024 drop-encryption + drop-ransom-notes pure- data-exfiltration extortion pivot ("more likely to get a ransom payment if the people notified are the CEO and key staff members rather than dropping ransom notes everywhere")

(11) signature OSINT- analysis-service for affiliates 10% of ransom payment per March 2024 administrator disclosure; (12) signature Oracle WebLogic exploitation initial access pattern per Forescout 2024 + Zerologon + SECRETSDUMP DCSYNC + DFSCoerce + NTDS. DIT extraction Active Directory compromise.

(13) signature .locked / .lock file extensions.

(14) cluster-defining July 4, 2025 official shutdown with 55 confirmed + 199 unconfirmed attacks total; (15) signature affiliate-base no-Russia-targeting operational principle aligning with Russian- cybercrime ecosystem signature.

cluster fills the October-2023-Hive-successor-emergence + Rust-based- encryptor-rewrite + data-exfiltration-priority- innovation + SharpRhino-AngryIP-Scanner-masquerade + MEGA-cloud-exfil + ICBC-London-6.6TB-attack + November-2024-farewell-then-return + late-2024- pure-data-exfil-pivot + July-2025-shutdown + Mihail-Kolesnikov-fake-identity-domain + 60- percent-Hive-code-overlap position in 2022-2025 post-takedown + emerging RaaS cell.

canonical illustration of post-takedown RaaS emergence + Hive-code-lineage-with-disputed-rebrand + Rust- based-encryptor-rewrite + data-exfiltration- priority-innovation + custom-backdoor-with- legitimate-tool-masquerade + Mihail-Kolesnikov- fake-identity-domain + November-2024-farewell- then-return + July-2025-shutdown lifecycle cited in essentially all subsequent post-takedown RaaS industry analyses through 2023-2026 period.

ransomware_raas_hive_lineage_disputed_rebrand confidence: high 24 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Hunters International (canonical naming) is a Rust- based Ransomware-as-a-Service (RaaS) operation emerging October 20, 2023 following FBI Hive takedown January 2023, with cluster-defining 60% code overlap with Hive ransomware confirming Hive lineage but operators publicly disputing rebrand characterization stating they acquired source code + infrastructure from former Hive operators as independent group. Independent RaaS with Hive ransomware code lineage attribution via @rivitna2 + @BushidoToken canonical October 20, 2023 first detection of 60% code overlap per Bitdefender + Acronis + Barracuda analysis + Russian-hosting + Mihail Kolesnikov fake-identity NiceNIC domain service registration signature shared with Rilide Infostealer + Snatch ransomware phishing domains. Standalone cluster paralleling embargo + cactus + trigona in v0.1.160 2022-2025 post-takedown + emerging RaaS cell.

Operational target profile
  • 200+ confirmed victims with 134 attacks first 7 months of 2024.
  • U.S. Marshals + FBI data leaks signature.
  • ICBC London Branch September 2024 (5.2M files + 6.6 TB)
  • Schneider Electric January 2024 + Anderson Oil & Gas November 2024 + Barber Specialties January 2025.
  • Multi-sector: healthcare + automotive + manufacturing + logistics + finance + education + food + oil/gas + industrial.
  • Russia explicitly avoided signature principle.
  • July 4, 2025 official shutdown with 55 confirmed + 199 unconfirmed total attacks Operational attack architecture: (1) 60% Hive code overlap (cluster-defining): per @rivitna2 + @BushidoToken October 20, 2023 detection (2) Rust-based encryptor rewrite (cluster- defining): from Hive's C + Golang variants for detection evasion + parallelism + cross-platform compatibility (3) Data-exfiltration-top-priority innovation (cluster-defining): departure from Hive encryption-first; per Bitdefender all victims data exfil, not all encrypted (4) SharpRhino custom backdoor (cluster- defining): AngryIP Scanner masquerade + NSIS- packed per Quorum Cyber (5) MEGA cloud storage exfil (cluster-defining) (6) Embedded encryption keys within encrypted files (signature): Rust tradecraft (7) Mihail Kolesnikov fake-identity NiceNIC domain signature (cluster-defining): shared with Rilide Infostealer + Snatch ransomware (8) Buffer.swp free-space wipe technique (cluster- defining) (9) November 2024 farewell letter then return (cluster-defining): exit-then-resume tradecraft (10) Late 2024 drop-encryption + drop-ransom- notes pure-data-exfil pivot (cluster-defining) (11) OSINT-analysis-service for affiliates 10% (signature): per March 2024 administrator disclosure (12) July 4 2025 official shutdown (cluster- defining): 55 confirmed + 199 unconfirmed attacks per SOCRadar The cluster fills the October-2023-Hive-successor- emergence + Rust-based-encryptor-rewrite + data- exfiltration-priority-innovation + SharpRhino- AngryIP-Scanner-masquerade + MEGA-cloud-exfil + ICBC-London-6.6TB + November-2024-farewell-then- return + late-2024-pure-data-exfil-pivot + July- 2025-shutdown + Mihail-Kolesnikov-fake-identity- domain + 60-percent-Hive-code-overlap position in 2022-2025 post-takedown + emerging RaaS cell.

Aliases

24
hunters_internationalhunters internationalhunters_intlhunters_intl_ransomwarehunters international ransomware-as-a-service raashunters international hive ransomware code 60 percent overlaphunters international rust-based encryptorhunters international october 2023 emergencehunters international data exfiltration top priority signaturehunters international sharprhino custom backdoor angryip scanner masqueradehunters international mega cloud storage exfiltrationhunters international 10th most active ransomware group 2024 quorum cyberhunters international 200 victims healthcare automotive manufacturing financehunters international icbc london branch 6.6 tb stolen september 2024hunters international u.s. marshals fbi leakshunters international anderson oil gas barber specialties victimshunters international mihail kolesnikov fake identity domain signaturehunters international november 2024 farewell letter then returnhunters international july 4 2025 official shutdownhunters international quorum cyber sharprhino disclosurehunters international .locked .lock file extensionhunters international avoids russia targeting affiliate basehunters international forescout oracle weblogic attack 2024hunters international embedded encryption keys within encrypted files

Notable Campaigns

12
2025Hunters International Official Shutdown (July 4, 2025)
2024Hunters International January 22, 2024 huntersinternational.org Surface Web Leak Site + Domain Reactivation
2024Hunters International March 2024 OSINT Analysis Service for Affiliates Signature
2024Hunters International ICBC London Branch Attack, 6.6 TB Stolen (September 2024)
2024Hunters International Quorum Cyber SharpRhino RAT Custom Backdoor Disclosure (2024)
2024Hunters International November 2024 Farewell Letter Exit Announcement Then Return Signature
2024Hunters International Late 2024 Drop-Encryption + Drop-Ransom-Notes Data-Only Pivot
2024Hunters International Schneider Electric January 2024 Attack
2024Hunters International Oracle WebLogic Attack Forescout Investigation (2024)
2024Hunters International 10th Most Active 2024 Ransomware Group (Quorum Cyber)
2023-2026Continued Industry Reference Status (2023-2026)
2023Hunters International Origin, October 20, 2023 Emergence + 60% Hive Code Overlap Detection

Attribution & Reporting

Attributed by
@rivitna2 / @BushidoToken (canonical October 20, 2023 first Hive code overlap detection)Bitdefender (canonical November 2023 Hive Ransomware's Offspring analysis)Acronis (canonical 2024 Hunters International new ransomware based on Hive source code analysis)Barracuda Networks (canonical July 2024 + December 2025 Your data is the prey analysis)Quorum Cyber (canonical 2024 SharpRhino RAT disclosure + threat actor profile)SOCRadar (canonical Dark Web Profile Hunters International July 2025 shutdown documentation)Picus Security (canonical February 2025 Hunters International Ransomware Tactics Impact Defense Strategies analysis)Forescout (canonical January 2025 Hunters International Ransomware Oracle WebLogic attack analysis)Daily Security Review (canonical February 2025 Hunters International Ransomware Hive Ransomware Ressurected analysis)Malware Hunter Team (canonical November 2023 leak site screenshots)Blackpoint Cyber (canonical August 2025 Hunters International Ransomware threat profile + November 2024 farewell-then-return documentation)Halcyon (canonical Anderson Oil & Gas + Barber Specialties + Hunters International attack tracking)Krishnan via SOCRadar (canonical Mihail Kolesnikov fake-identity domain analysis)The Register (canonical September 2024 ICBC London cyber-gang extortion coverage)FBI / Germany / Netherlands law enforcement (canonical January 2023 Hive takedown + 7-month covert infiltration documentation)
Key reporting
reportBitdefender: Hive Ransomware's Offspring, Hunters International Takes the Stage (November 2023), canonical first public analysis
reportAcronis: Hunters International, New ransomware based on Hive source code (2024)
reportBarracuda Networks: Hunters International, Your data is the prey (July 2024 + December 2025)
reportQuorum Cyber: From Hunters to Hunted, Quorum Cyber Exposes New Hunters International Malware (2024 SharpRhino RAT disclosure)
reportSOCRadar: Dark Web Profile, Hunters International (July 2025), canonical July 4, 2025 shutdown documentation
reportPicus Security: Hunters International Ransomware, Tactics, Impact, and Defense Strategies (February 2025)
reportForescout: Hunters International Ransomware, What We Learned (January 2025), Oracle WebLogic attack analysis
reportBlackpoint Cyber: Hunters International Ransomware Threat Profile (August 2025)
reportDaily Security Review: Hunters International Ransomware, Hive Ransomware Ressurected (February 2025)
report@rivitna2 / @BushidoToken (Will Thomas): canonical October 20, 2023 first Hive code overlap detection
reportHalcyon: canonical Anderson Oil & Gas + Barber Specialties attack documentation
reportThe Register / J. Lyons: canonical September 11, 2024 ICBC London cyber-gang extortion coverage

Operational

State sponsor

Independent Ransomware-as-a-Service (RaaS) operation with Hive ransomware code lineage (60%+ overlap) acquired via source code + infrastructure purchase from former Hive operators per group's own public statement. Group publicly disputes rebrand characterization while industry consensus suggests operator continuity at minimum. Russian-hosting + Russian-domain-registration signature with Mihail Kolesnikov fake-identity NiceNIC domain service registration tradecraft consistent with broader Russian-aligned cybercrime ecosystem.

affiliate- base no-Russia-targeting principle aligns with Russian-cybercrime operational signature. Attribution chain: (1) @rivitna2 + @BushidoToken canonical October 20 2023 code-overlap-detection: per Bitdefender: "On October 20th, 2023, security researcher @rivitna2 was the first to detect code similarities between Hunters International and Hive ransomware samples. @BushidoToken also found multiple code overlaps and similarities, reporting at least a 60% match between the two sets of code. The initial consensus in the security industry was that Hunters International is a rebranded version of Hive, a practice often observed among cybercriminals following a significant disruption." (2) Group's public dispute of rebrand characterization: per Bitdefender: "In an uncommon statement, which is the sole communication from the group thus far, Hunters International addressed these speculations. They declared that, rather than being a rebranded iteration of Hive, they are an independent ransomware group that acquired the source code and infrastructure from Hive. Hunters International claimed to have a primary focus on data exfiltration rather than data encryption." (3) Barracuda Networks canonical 60% code overlap + Rust + improvements documentation: per Barracuda: "When Hunters International emerged, researchers found that 60% of its code overlapped with Hive... Hunters made many improvements to the Hive code, including the following: Corrected 'several issues that sometimes prevented file decryption' in Hive's original encryption logic. Reduced command-line parameters and streamlined the process of encryption key storage. Rebuilt the code in Rust, which earlier Hive versions written in C and Golang." (4) Acronis canonical Hive-takeover-and-fix forensic analysis: per Acronis: "Hunters International ransomware was first spotted in October 2023. While it shares many similarities with Hive ransomware, it is not a rebrand, as threat actors said. After the FBI defaced the Hive ransomware leak site, Hunters International sold older versions of their source code written in C and Golang, as well as their website... As Hunters International threat actors said, they took Hive encryption logic and fixed several issues that sometimes prevented file decryption." (5) Quorum Cyber canonical SharpRhino RAT disclosure: per Quorum Cyber: "In 2024, security researchers with Quorum Cyber reported a Hunters International custom backdoor, SharpRhino." Per Daily Security Review: "SharpRhino, a custom backdoor developed by Hunters International, masquerading as the legitimate tool AngryIP Scanner. This backdoor is packed using NSIS (Nullsoft Scriptable Install System)." (6) SOCRadar canonical Dark Web Profile + July 2025 shutdown documentation: per SOCRadar: "Hunters International was officially shut down on July 4, 2025, after carrying out 55 confirmed and 199 unconfirmed attacks." Operational mission objective: Financially-motivated RaaS double-extortion with cluster-defining data-exfiltration-priority innovation over Hive encryption-first approach; data exfiltration via MEGA cloud storage signature; affiliate operations across multiple sectors and countries with explicit no-Russia-targeting principle.

OSINT-analysis-service offering for affiliates (10% of ransom payment per March 2024 administrator disclosure).

Operational target profile
  • 200+ confirmed victims across operational lifetime per Picus Security + 134 attacks in first 7 months of 2024 per Quorum Cyber.
  • U.S. Marshals + FBI data leaks signature.
  • Industrial and Commercial Bank of China (ICBC) London Branch September 2024 (5.2M files + 6.6 TB stolen)
  • Schneider Electric January 2024 victim.
  • Anderson Oil & Gas November 2024 victim.
  • Barber Specialties January 2025 victim.
  • Multi-sector: healthcare + automotive + manufacturing + logistics + finance + education + food.
  • United States + United Kingdom + Germany + Japan + Brazil primary geographic targets.
  • Russia explicitly avoided per signature operational principle.
  • Final operational period: July 4, 2025 shutdown (55 confirmed + 199 unconfirmed attacks total per SOCRadar) The cluster fills the October-2023-Hive-successor- emergence + Rust-based-encryptor-rewrite + data- exfiltration-priority-innovation + SharpRhino- AngryIP-Scanner-masquerade + MEGA-cloud-exfil + ICBC-London-6.6TB-attack + November-2024-farewell- then-return + July-2025-shutdown + Mihail- Kolesnikov-fake-identity-domain + 60-percent-Hive- code-overlap position in 2022-2025 post-takedown + emerging RaaS cell.
Motivations
financially_motivated_ransomware_as_a_service_double_extortion, data_exfiltration_top_priority_innovation_over_hive_encryption_first, hive_ransomware_source_code_infrastructure_acquisition_signature, rust_based_encryptor_rewrite_signature_capability, affiliate_base_no_russia_targeting_operational_principle, osint_analysis_service_offering_10_percent_affiliate_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)35/60 · 58%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGA CLOUD STORAGEMIHAIL KOLESNIKOV FAKE IDENTITY NICENIC DOMAIN SERVICE 400+ DOMAINS SIGNATURESHARPRHINO ANGRYIP SCANNER MASQUERADE NSIS NULLSOFT SCRIPTABLE INSTALL SYSTEM PACKEDSHARPRHINO RAT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin