Skip to main content

Operator dossier

hunters (also tracked as Hunters International) is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 307 public victims claimed by this operator between October 20, 2023 and May 27, 2025. Hunters is a ransomware group that emerged in October 2023, operating with primarily financial motivations and demonstrating a preference for targeting business-critical sectors across English-speaking nations and Western Europe. The group has claimed responsibility for attacks against 307 victims, with their operations heavily concentrated in the United States, United Kingdom, Canada, France, and Spain, while focusing predominantly on business services, manufacturing, technology, and healthcare organizations. Due to the group's relatively recent emergence and limited public documentation from major cybersecurity agencies, detailed information about their specific attack methodologies, toolsets, and operational structure remains sparse in publicly available threat intelligence reports. The group's targeting pattern suggests a strategic focus on sectors with high operational dependencies and potential for significant business disruption, which aligns with typical ransomware monetization strategies. Given the recency of their first observed activities in late 2023, comprehensive analysis of their tactics, techniques, and procedures by established security research organizations is still developing. Hunters appears to remain active as of current reporting, though the limited timeframe since their emergence makes long-term operational assessment challenging without additional confirmed incident data from authoritative sources.

Most-targeted sectors

Most-affected countries

Recent disclosures by hunters

Most recent 30 of 307 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for hunters

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

hunters

aka Hunters International · 307 victims indexed · first seen 3 years ago · last activity 1 year ago

307
Victims indexed
#29 of 356 tracked operators
1y 7m
Active period
Oct 2023 → May 2025
10
Countries hit
top US · 149

At a glance

Status
inactive
Aliases
Hunters International
First seen
3 years ago
Last activity
1 year ago
Onion sites
4 known endpoints
Primary sector
Business Services · 58 hits

About

Hunters is a ransomware group that emerged in October 2023, operating with primarily financial motivations and demonstrating a preference for targeting business-critical sectors across English-speaking nations and Western Europe. The group has claimed responsibility for attacks against 307 victims, with their operations heavily concentrated in the United States, United Kingdom, Canada, France, and Spain, while focusing predominantly on business services, manufacturing, technology, and healthcare organizations. Due to the group's relatively recent emergence and limited public documentation from major cybersecurity agencies, detailed information about their specific attack methodologies, toolsets, and operational structure remains sparse in publicly available threat intelligence reports. The group's targeting pattern suggests a strategic focus on sectors with high operational dependencies and potential for significant business disruption, which aligns with typical ransomware monetization strategies. Given the recency of their first observed activities in late 2023, comprehensive analysis of their tactics, techniques, and procedures by established security research organizations is still developing. Hunters appears to remain active as of current reporting, though the limited timeframe since their emergence makes long-term operational assessment challenging without additional confirmed incident data from authoritative sources.

References

4 links

External sources curated by the MISP threat-intel community.

Timeline

20 months
2023-10-01T00:00:00+00:00 · 22023-11-01T00:00:00+00:00 · 172023-12-01T00:00:00+00:00 · 62024-01-01T00:00:00+00:00 · 142024-02-01T00:00:00+00:00 · 322024-03-01T00:00:00+00:00 · 192024-04-01T00:00:00+00:00 · 302024-05-01T00:00:00+00:00 · 112024-06-01T00:00:00+00:00 · 82024-07-01T00:00:00+00:00 · 262024-08-01T00:00:00+00:00 · 192024-09-01T00:00:00+00:00 · 142024-10-01T00:00:00+00:00 · 232024-11-01T00:00:00+00:00 · 242024-12-01T00:00:00+00:00 · 152025-01-01T00:00:00+00:00 · 92025-02-01T00:00:00+00:00 · 102025-03-01T00:00:00+00:00 · 62025-04-01T00:00:00+00:00 · 172025-05-01T00:00:00+00:00 · 5
2023-10-01T00:00:00+00:002025-05-01T00:00:00+00:00

Top countries

🇺🇸 United States
149
🇬🇧 United Kingdom
16
🇨🇦 Canada
14
🇫🇷 France
12
🇩🇪 Germany
9
🇪🇸 Spain
9
🇮🇹 Italy
8
🇯🇵 Japan
6

Top sectors

Business Services
58
Manufacturing
42
Technology
34
Healthcare
26
Energy
20
Transportation/Logistics
16
Government
12
Financial
12

Recent victims

Loading…

Onion infrastructure

4 known
  • http://hunters33mmcwww7ek7q5ndahul6nmzmrsumfs6aenicbqon6mxfiqyd.onion
  • http://hunters55atbdusuladzv7vzv6a423bkh6ksl2uftwrxyuarbzlfh7yd.onion
  • http://hunters55rdxciehoqzwv7vgyv6nt37tbwax2reroyzxhou7my5ejyid.onion
  • http://huntersinternational.net

Source

Updated 1 year ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time hunters posts a victim.

Add hunters to your watchlist — Pro pings you within 5 minutes of any new hunters leak-site post, Telegram callout, or affiliate-rebrand inference.