Hunters International
Hunters International (canonical naming) is a Rust- based Ransomware-as-a-Service (RaaS) operation emerging October 20, 2023 following FBI Hive takedown January 2023, with cluster-defining 60% code overlap with Hive ransomware confirming Hive lineage per @rivitna2 + @BushidoToken canonical October 20, 2023 detection while operators publicly disputing rebrand characterization stating they acquired source code + infrastructure from former Hive operators as independent group ("In an uncommon statement, which is the sole communication from the group thus far, Hunters International addressed these speculations. They declared that, rather than being a rebranded iteration of Hive, they are an independent ransomware group that acquired the source code and infrastructure from Hive. Hunters International claimed to have a primary focus on data exfiltration rather than data encryption")
independent RaaS with Hive lineage attribution via Bitdefender November 2023 canonical analysis + Acronis 2024 + Barracuda + Quorum Cyber SharpRhino disclosure + SOCRadar Dark Web Profile + Picus Security + Forescout + Blackpoint + Daily Security Review industry coverage + Russian-hosting + Mihail Kolesnikov fake-identity NiceNIC domain service registration signature shared with Rilide Infostealer + Snatch ransomware phishing domains; standalone cluster paralleling embargo + cactus + trigona in v0.1.160 2022-2025 post-takedown + emerging RaaS cell.
operational target profile 200+ confirmed victims with 134 attacks first 7 months of 2024 + 10th most active 2024 ransomware group per Quorum Cyber + signature high-profile victims including U.S. Marshals + FBI data leaks + ICBC London Branch September 2024 (5.2 million files + 6.6 TB stolen per Picus Security) + Schneider Electric January 2024 + Anderson Oil & Gas November 2024 + Barber Specialties January 2025 + multi-sector across healthcare + automotive + manufacturing + logistics + finance + education + food + oil/gas + industrial across United States + United Kingdom + Germany + Japan + Brazil with Russia explicitly avoided per signature operational principle.
July 4, 2025 official shutdown with 55 confirmed + 199 unconfirmed attacks total per SOCRadar marking ~21-month operational lifecycle; operational attack architecture: (1) cluster- defining 60% Hive ransomware source code overlap per @rivitna2 + @BushidoToken October 20, 2023 detection establishing Hive lineage.
(2) cluster- defining Rust-based encryptor rewrite from Hive's earlier C + Golang variants for detection evasion + parallelism + cross-platform compatibility per Bitdefender ("Rust is gaining favor among ransomware operators, with another notable example being BlackCat, due to its relative resilience to reverse engineering by security researchers, robust control over low-level resources, excellent support for parallelism crucial for swift file encryption, and a wide array of cryptographic libraries")
(3) cluster-defining data-exfiltration-top-priority innovation over Hive encryption-first approach per Bitdefender ("the group's focus significantly leans towards stealing data, as evidenced by all known victims experiencing data exfiltration, whereas not every victim's data was encrypted"); (4) cluster-defining SharpRhino custom backdoor with AngryIP Scanner legitimate-tool masquerade + NSIS (Nullsoft Scriptable Install System) packing per Quorum Cyber 2024 disclosure.
(5) cluster- defining MEGA cloud storage data exfiltration tradecraft per Forescout Oracle WebLogic investigation.
(6) signature embedded-encryption- keys-within-encrypted-files Rust tradecraft complicating decryption analysis while streamlining paying-victim recovery.
(7) cluster-defining Mihail Kolesnikov fake-identity NiceNIC domain service registration signature with 400+ domains shared with Rilide Infostealer + Snatch ransomware phishing per SOCRadar + Blackpoint with huntersinternational.org legitimate-2017-2021- domain reactivated January 2024 for surface-web leak site.
(8) cluster-defining buffer.swp free- space wipe technique with 16,384 bytes random data continuously written until disk full preventing recovery.
(9) cluster-defining November 2024 farewell letter exit announcement then weeks-later return per Blackpoint signature exit-then-resume tradecraft.
(10) cluster-defining late-2024 drop-encryption + drop-ransom-notes pure- data-exfiltration extortion pivot ("more likely to get a ransom payment if the people notified are the CEO and key staff members rather than dropping ransom notes everywhere")
(11) signature OSINT- analysis-service for affiliates 10% of ransom payment per March 2024 administrator disclosure; (12) signature Oracle WebLogic exploitation initial access pattern per Forescout 2024 + Zerologon + SECRETSDUMP DCSYNC + DFSCoerce + NTDS. DIT extraction Active Directory compromise.
(13) signature .locked / .lock file extensions.
(14) cluster-defining July 4, 2025 official shutdown with 55 confirmed + 199 unconfirmed attacks total; (15) signature affiliate-base no-Russia-targeting operational principle aligning with Russian- cybercrime ecosystem signature.
cluster fills the October-2023-Hive-successor-emergence + Rust-based- encryptor-rewrite + data-exfiltration-priority- innovation + SharpRhino-AngryIP-Scanner-masquerade + MEGA-cloud-exfil + ICBC-London-6.6TB-attack + November-2024-farewell-then-return + late-2024- pure-data-exfil-pivot + July-2025-shutdown + Mihail-Kolesnikov-fake-identity-domain + 60- percent-Hive-code-overlap position in 2022-2025 post-takedown + emerging RaaS cell.
canonical illustration of post-takedown RaaS emergence + Hive-code-lineage-with-disputed-rebrand + Rust- based-encryptor-rewrite + data-exfiltration- priority-innovation + custom-backdoor-with- legitimate-tool-masquerade + Mihail-Kolesnikov- fake-identity-domain + November-2024-farewell- then-return + July-2025-shutdown lifecycle cited in essentially all subsequent post-takedown RaaS industry analyses through 2023-2026 period.