Inactive ransomware operator
← All groupshunters
aka Hunters International · 307 victims indexed · first seen 3 years ago · last activity 1 year ago
At a glance
- Status
- inactive
- Aliases
- Hunters International
- First seen
- 3 years ago
- Last activity
- 1 year ago
- Onion sites
- 4 known endpoints
- Primary sector
- Business Services · 71 hits
About
References
4 linksExternal sources curated by the MISP threat-intel community.
Timeline
20 monthsTop countries
Top sectors
MITRE ATT&CK
34 techniques · 10 tacticsTactics
Techniques
- T1190Exploit Public-Facing Application
- T1133External Remote Services
- T1078Valid Accounts
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.003Windows Command Shell
- T1047Windows Management Instrumentation
- T1548Abuse Elevation Control Mechanism
- T1548.002Bypass User Account Control
- T1134Access Token Manipulation
- T1562Impair Defenses
- T1562.001Disable or Modify Tools
- T1070Indicator Removal
- T1027Obfuscated Files or Information
- T1003OS Credential Dumping
- T1003.001LSASS Memory
- T1110Brute Force
- T1057Process Discovery
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1135Network Share Discovery
- T1018Remote System Discovery
- T1021Remote Services
- T1021.001Remote Desktop Protocol
- T1021.002SMB/Windows Admin Shares
- T1570Lateral Tool Transfer
- T1005Data from Local System
- T1039Data from Network Shared Drive
- T1048Exfiltration Over Alternative Protocol
- T1567Exfiltration Over Web Service
- T1486Data Encrypted for Impact
- T1490Inhibit System Recovery
- T1489Service Stop
- T1657Financial Theft
Recent victims
Loading…
Onion infrastructure
4 known- http://hunters33mmcwww7ek7q5ndahul6nmzmrsumfs6aenicbqon6mxfiqyd.onion
- http://hunters55atbdusuladzv7vzv6a423bkh6ksl2uftwrxyuarbzlfh7yd.onion
- http://hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion
- http://huntersinternational.net
Source
Updated 1 year agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
Get alerted the next time hunters posts a victim.
Add hunters to your watchlist — Pro pings you within 5 minutes of any new hunters leak-site post, Telegram callout, or affiliate-rebrand inference.

