Overview
Platforms:
—
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
Domain Accounts
Top countries:
—
Observed sectors:
—
Tracked victims:
307
Attribution
Water Ouroboros
VERIFIED
Vendor tracking name
Trend Micro tracks Hunters International ransomware activity under the Water Ouroboros designation.
Hive
PROBABLE
Probable predecessor / lineage relationship
Hunters International ransomware contains substantial technical overlap with Hive. Group-IB assesses with moderate confidence that former Hive operators may have been involved in Hunters International administration, while Hunters International itself claimed it purchased Hive source code and infrastructure.
Affiliates
No affiliate information available.
Activity
Recent Observations
Final known Hunters International victim publications
May 2025
Operational decline
Hunters International's final known victim claims appeared in late May 2025 as the operation shifted toward the World Leaks extortion project.
Fortinet exploitation followed by ransomware deployment
February 2025
Incident response
eSentire documented a Hunters International intrusion in which CVE-2024-55591 was exploited for initial access, followed by VPN access, RDP, reconnaissance, data exfiltration and ransomware deployment.
World Leaks project launched
January 2025
Operational transition
Hunters International administrators launched World Leaks as an extortion-focused project designed to prioritize data theft over file encryption.
Stealth-focused ransomware version released
August 2024
Ransomware development
Hunters International introduced ransomware versions designed to avoid changing encrypted file extensions and to omit widespread ransom-note deployment, reducing visibility during negotiations.
SharpRhino RAT documented
August 2024
Malware activity
Quorum Cyber documented SharpRhino, a remote-access trojan used during an intrusion attributed to Hunters International. Available evidence indicates that SharpRhino may have been associated with a specific affiliate rather than being a universal Hunters International capability.
TTPs
ATT&CK coverage:
12 techniques
· 8 tactics
T1059
Command and Scripting Interpreter
VERIFIEDExecution
Hunters International ransomware supports command-line arguments allowing operators to control encryption targets, remote shares and execution behavior.
T1078.002
Domain Accounts
VERIFIEDPrivilege Escalation / Lateral Movement
The ransomware supports administrator credentials for accessing remote systems and network shares.
T1562.001
Impair Defenses
VERIFIEDDefense Evasion
Hunters International tooling can disable security controls, including ESXi execInstalledOnly enforcement, to facilitate unauthorized code execution.
Show more TTPs (9)
T1497.003
Time Based Evasion
VERIFIEDDefense Evasion
Hunters International ransomware supports configurable execution delays intended to complicate sandbox and automated malware analysis.
T1057
Process Discovery
VERIFIEDDiscovery
The ransomware enumerates running processes and services before encryption.
T1135
Network Share Discovery
VERIFIEDDiscovery
Hunters International ransomware enumerates and accesses local and remote network shares as potential encryption targets.
T1021.002
SMB / Windows Admin Shares
VERIFIEDLateral Movement
Hunters International supports access to remote SMB and Windows administrative shares for remote encryption activity.
T1090.003
Multi-hop Proxy
VERIFIEDCommand and Control
Hunters International Storage Software used proxy infrastructure, including Tor, when communicating with group-controlled services.
T1020
Automated Exfiltration
VERIFIEDExfiltration
Storage Software indexed stolen files and integrated their metadata into Hunters International victim and affiliate systems, enabling structured management of exfiltrated information.
T1490
Inhibit System Recovery
VERIFIEDImpact
The ransomware deletes shadow copies and Windows backup information and disables recovery functionality before encryption.
T1489
Service Stop
VERIFIEDImpact
Hunters International terminates configured services and processes that could interfere with encryption.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Hunters International ransomware encrypts victim data using per-file AES keys and supports local, remote-share and virtualization environments.
Victims
CVEs
Fortinet
— FortiOS / FortiProxy
eSentire directly observed exploitation of CVE-2024-55591 for initial access during a February 2025 intrusion attributed to Hunters International.
Associated since:
February 2025
Infrastructure
Hunters International leak site
Hunters International maintained Tor and clear-web leak infrastructure used for victim publication and data-extortion activity.
Hunters International affiliate panel
Hunters International operated an affiliate panel supporting target registration, ransom pricing, payment tracking, disclosure management and access to operation-specific tooling.
Storage Software
Hunters International provided affiliates with dedicated Windows and Linux software that indexed stolen data, communicated metadata to the group's platform and connected affiliate-controlled storage to victim-facing disclosure systems.
Multi-platform ransomware
Hunters International maintained ransomware builds supporting Windows, Linux, FreeBSD, SunOS and VMware ESXi across x86, x64 and ARM architectures.
Timeline
2025-07
Hunters International formally closes
Hunters International publicly announced closure of the project and offered decryption tools to previous victims.
2025-05
Final known Hunters International victim claims
The original Hunters International operation stopped publishing new victim claims as activity transitioned toward World Leaks.
2025-02
CVE-2024-55591 exploitation documented
eSentire observed a Hunters International intrusion beginning with exploitation of a Fortinet authentication-bypass vulnerability and ending in data theft and ransomware encryption.
Show more events (5)
2025-01
World Leaks launched
Individuals associated with Hunters International administration launched World Leaks as an extortion-focused project centered on data theft rather than ransomware encryption.
2024-11
Internal closure announcement
Hunters International administrators informed partners that the ransomware project would close because encryption-based ransomware had become increasingly risky and less profitable.
2024-08
Ransomware adopts stealth-focused extortion changes
New ransomware versions stopped automatically changing encrypted file extensions and broadly distributing ransom notes, supporting a quieter negotiation strategy.
2024-04
Hunters International becomes a major ransomware operation
U.S. healthcare-sector threat intelligence ranked Hunters International among the most active ransomware operations observed during early 2024.
2023-10
Hunters International emerges
Hunters International began public operations in October 2023 with victim disclosures and ransomware samples appearing shortly afterward.
Sources
HC3 Top 10 Most Active Ransomware Groups
U.S. Department of Health and Human Services / HC3
Show more sources (4)
From Access to Encryption: Dissecting Hunters International's Latest Ransomware Attack
eSentire Threat Response Unit
Hunters International ransomware group claims to be shutting down
Recorded Future News
Incident report