Skip to main content

Operator dossier

hunters (also tracked as Hunters International) is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 307 public victims claimed by this operator between October 20, 2023 and May 27, 2025. Hunters International is a ransomware group first observed in October 2023 that operates with primary financial motivations, having claimed responsibility for attacks against at least 307 known victims across a broad range of sectors and geographies. The group is believed to have acquired the source code and infrastructure of the defunct Hive ransomware operation following Hive's disruption by law enforcement in January 2023, though Hunters International has publicly disputed characterizations that it is a direct Hive rebrand, asserting instead that it independently purchased the codebase; the group operates as a Ransomware-as-a-Service model, recruiting affiliates to conduct intrusions on its behalf. Hunters International employs double extortion tactics, exfiltrating victim data prior to encryption and threatening public release on a dedicated leak site to increase pressure on victims to pay; initial access vectors observed across reported incidents include phishing, exploitation of publicly exposed remote services, and credential abuse, with the group deploying its Rust-based encryptor derived from Hive's codebase. The group has demonstrated a notably indiscriminate targeting pattern, with victims concentrated in the United States, United Kingdom, Canada, France, and Germany spanning Business Services, Manufacturing, Technology, Healthcare, and Energy sectors, reflecting a financially opportunistic rather than strategically selective approach; no single landmark ransom payment or named high-profile campaign has been singularly attributed to the group in major public reporting as of available documentation. As of the most recent publicly available threat intelligence reporting, Hunters International remains an active and operational ransomware threat with a growing victim count and no confirmed law enforcement disruption or rebranding.

Most-targeted sectors

Most-affected countries

Recent disclosures by hunters

Most recent 150 of 307 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for hunters

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

hunters

aka Hunters International · 307 victims indexed · first seen 3 years ago · last activity 1 year ago

307
Victims indexed
#30 of 370 tracked operators
1y 7m
Active period
Oct 2023 → May 2025
30
Countries hit
top US · 150

At a glance

Status
inactive
Aliases
Hunters International
First seen
3 years ago
Last activity
1 year ago
Onion sites
4 known endpoints
Primary sector
Business Services · 71 hits

About

Hunters International is a ransomware group first observed in October 2023 that operates with primary financial motivations, having claimed responsibility for attacks against at least 307 known victims across a broad range of sectors and geographies. The group is believed to have acquired the source code and infrastructure of the defunct Hive ransomware operation following Hive's disruption by law enforcement in January 2023, though Hunters International has publicly disputed characterizations that it is a direct Hive rebrand, asserting instead that it independently purchased the codebase; the group operates as a Ransomware-as-a-Service model, recruiting affiliates to conduct intrusions on its behalf. Hunters International employs double extortion tactics, exfiltrating victim data prior to encryption and threatening public release on a dedicated leak site to increase pressure on victims to pay; initial access vectors observed across reported incidents include phishing, exploitation of publicly exposed remote services, and credential abuse, with the group deploying its Rust-based encryptor derived from Hive's codebase. The group has demonstrated a notably indiscriminate targeting pattern, with victims concentrated in the United States, United Kingdom, Canada, France, and Germany spanning Business Services, Manufacturing, Technology, Healthcare, and Energy sectors, reflecting a financially opportunistic rather than strategically selective approach; no single landmark ransom payment or named high-profile campaign has been singularly attributed to the group in major public reporting as of available documentation. As of the most recent publicly available threat intelligence reporting, Hunters International remains an active and operational ransomware threat with a growing victim count and no confirmed law enforcement disruption or rebranding.

References

4 links

External sources curated by the MISP threat-intel community.

Timeline

20 months
2023-10-01T00:00:00+00:00 · 22023-11-01T00:00:00+00:00 · 172023-12-01T00:00:00+00:00 · 62024-01-01T00:00:00+00:00 · 142024-02-01T00:00:00+00:00 · 322024-03-01T00:00:00+00:00 · 192024-04-01T00:00:00+00:00 · 302024-05-01T00:00:00+00:00 · 112024-06-01T00:00:00+00:00 · 82024-07-01T00:00:00+00:00 · 262024-08-01T00:00:00+00:00 · 192024-09-01T00:00:00+00:00 · 142024-10-01T00:00:00+00:00 · 232024-11-01T00:00:00+00:00 · 242024-12-01T00:00:00+00:00 · 152025-01-01T00:00:00+00:00 · 92025-02-01T00:00:00+00:00 · 102025-03-01T00:00:00+00:00 · 62025-04-01T00:00:00+00:00 · 172025-05-01T00:00:00+00:00 · 5
2023-10-01T00:00:00+00:002025-05-01T00:00:00+00:00

Top countries

🇺🇸 United States
150
🇬🇧 United Kingdom
16
🇨🇦 Canada
15
🇫🇷 France
12
🇩🇪 Germany
9
🇪🇸 Spain
9
🇮🇹 Italy
8
🇯🇵 Japan
6

Top sectors

Business Services
71
Manufacturing
50
Technology
35
Healthcare
34
Energy
22
Transportation/Logistics
16
Public Sector
16
Financial Services
13

MITRE ATT&CK

34 techniques · 10 tactics

Tactics

Initial AccessExecutionPrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationImpact

Techniques

Recent victims

Loading…

Onion infrastructure

4 known
  • http://hunters33mmcwww7ek7q5ndahul6nmzmrsumfs6aenicbqon6mxfiqyd.onion
  • http://hunters55atbdusuladzv7vzv6a423bkh6ksl2uftwrxyuarbzlfh7yd.onion
  • http://hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion
  • http://huntersinternational.net

Source

Updated 1 year ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time hunters posts a victim.

Add hunters to your watchlist — Pro pings you within 5 minutes of any new hunters leak-site post, Telegram callout, or affiliate-rebrand inference.