Overview

Platforms: —
Variants: —
Extensions: —
ATT&CK software: —
Initial access: Domain Accounts
Top countries: —
Observed sectors: —
Tracked victims: 307

Attribution

Water Ouroboros VERIFIED
Vendor tracking name
Trend Micro tracks Hunters International ransomware activity under the Water Ouroboros designation.
Hive PROBABLE
Probable predecessor / lineage relationship
Hunters International ransomware contains substantial technical overlap with Hive. Group-IB assesses with moderate confidence that former Hive operators may have been involved in Hunters International administration, while Hunters International itself claimed it purchased Hive source code and infrastructure.

Affiliates

No affiliate information available.

Activity

Recent Observations

Final known Hunters International victim publications
May 2025
Operational decline
Hunters International's final known victim claims appeared in late May 2025 as the operation shifted toward the World Leaks extortion project.
Fortinet exploitation followed by ransomware deployment
February 2025
Incident response
eSentire documented a Hunters International intrusion in which CVE-2024-55591 was exploited for initial access, followed by VPN access, RDP, reconnaissance, data exfiltration and ransomware deployment.
World Leaks project launched
January 2025
Operational transition
Hunters International administrators launched World Leaks as an extortion-focused project designed to prioritize data theft over file encryption.
Stealth-focused ransomware version released
August 2024
Ransomware development
Hunters International introduced ransomware versions designed to avoid changing encrypted file extensions and to omit widespread ransom-note deployment, reducing visibility during negotiations.
SharpRhino RAT documented
August 2024
Malware activity
Quorum Cyber documented SharpRhino, a remote-access trojan used during an intrusion attributed to Hunters International. Available evidence indicates that SharpRhino may have been associated with a specific affiliate rather than being a universal Hunters International capability.

TTPs

ATT&CK coverage: 12 techniques · 8 tactics
T1059 Command and Scripting Interpreter
VERIFIED
Execution
Hunters International ransomware supports command-line arguments allowing operators to control encryption targets, remote shares and execution behavior.
T1078.002 Domain Accounts
VERIFIED
Privilege Escalation / Lateral Movement
The ransomware supports administrator credentials for accessing remote systems and network shares.
T1562.001 Impair Defenses
VERIFIED
Defense Evasion
Hunters International tooling can disable security controls, including ESXi execInstalledOnly enforcement, to facilitate unauthorized code execution.
Show more TTPs (9)
T1497.003 Time Based Evasion
VERIFIED
Defense Evasion
Hunters International ransomware supports configurable execution delays intended to complicate sandbox and automated malware analysis.
T1057 Process Discovery
VERIFIED
Discovery
The ransomware enumerates running processes and services before encryption.
T1135 Network Share Discovery
VERIFIED
Discovery
Hunters International ransomware enumerates and accesses local and remote network shares as potential encryption targets.
T1021.002 SMB / Windows Admin Shares
VERIFIED
Lateral Movement
Hunters International supports access to remote SMB and Windows administrative shares for remote encryption activity.
T1090.003 Multi-hop Proxy
VERIFIED
Command and Control
Hunters International Storage Software used proxy infrastructure, including Tor, when communicating with group-controlled services.
T1020 Automated Exfiltration
VERIFIED
Exfiltration
Storage Software indexed stolen files and integrated their metadata into Hunters International victim and affiliate systems, enabling structured management of exfiltrated information.
T1490 Inhibit System Recovery
VERIFIED
Impact
The ransomware deletes shadow copies and Windows backup information and disables recovery functionality before encryption.
T1489 Service Stop
VERIFIED
Impact
Hunters International terminates configured services and processes that could interfere with encryption.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Hunters International ransomware encrypts victim data using per-file AES keys and supports local, remote-share and virtualization environments.

Victims

CVEs

Fortinet — FortiOS / FortiProxy
eSentire directly observed exploitation of CVE-2024-55591 for initial access during a February 2025 intrusion attributed to Hunters International.
Associated since: February 2025

Infrastructure

Hunters International leak site
Hunters International maintained Tor and clear-web leak infrastructure used for victim publication and data-extortion activity.
Hunters International affiliate panel
Hunters International operated an affiliate panel supporting target registration, ransom pricing, payment tracking, disclosure management and access to operation-specific tooling.
Storage Software
Hunters International provided affiliates with dedicated Windows and Linux software that indexed stolen data, communicated metadata to the group's platform and connected affiliate-controlled storage to victim-facing disclosure systems.
Multi-platform ransomware
Hunters International maintained ransomware builds supporting Windows, Linux, FreeBSD, SunOS and VMware ESXi across x86, x64 and ARM architectures.

Timeline

2025-07
Hunters International formally closes
Hunters International publicly announced closure of the project and offered decryption tools to previous victims.
2025-05
Final known Hunters International victim claims
The original Hunters International operation stopped publishing new victim claims as activity transitioned toward World Leaks.
2025-02
CVE-2024-55591 exploitation documented
eSentire observed a Hunters International intrusion beginning with exploitation of a Fortinet authentication-bypass vulnerability and ending in data theft and ransomware encryption.
Show more events (5)
2025-01
World Leaks launched
Individuals associated with Hunters International administration launched World Leaks as an extortion-focused project centered on data theft rather than ransomware encryption.
2024-11
Internal closure announcement
Hunters International administrators informed partners that the ransomware project would close because encryption-based ransomware had become increasingly risky and less profitable.
2024-08
Ransomware adopts stealth-focused extortion changes
New ransomware versions stopped automatically changing encrypted file extensions and broadly distributing ransom notes, supporting a quieter negotiation strategy.
2024-04
Hunters International becomes a major ransomware operation
U.S. healthcare-sector threat intelligence ranked Hunters International among the most active ransomware operations observed during early 2024.
2023-10
Hunters International emerges
Hunters International began public operations in October 2023 with victim disclosures and ransomware samples appearing shortly afterward.

Sources