WorldLeaks, also styled World Leaks, is a financially motivated cybercriminal data-extortion operation that succeeded Hunters International. Hunters International emerged in mid-2023 as a ransomware-as-a-service operation and shut down under that name on July 4, 2025. WorldLeaks continued operating with an emphasis on stealing data and demanding payment under threats of public disclosure rather than encrypting victim systems. Its targets include healthcare providers, retailers, and manufacturing organizations, with a substantial focus on United States-based organizations. It has also claimed attacks against Indian electronics businesses and contractors associated with a nuclear power project. Hunters International conducted double-extortion attacks using ransomware and a dedicated data leak site. Its ransomware shares code with Hive, and Hunters International acknowledged acquiring Hive source code; this code lineage does not establish that the two operations had the same operators. Observed Hunters International intrusions exploited CVE-2024-55591 in Fortinet products to obtain initial access, create privileged accounts, and establish VPN access. Other intrusions began with malvertising and trojanized administrative software delivering SMOKEDHAM or SharpRhino backdoors. Attackers maintained access through persistent backdoors and legitimate remote-access software, performed Active Directory and network reconnaissance, and moved laterally using RDP and reverse SSH tunnels. Data theft involved archiving file shares and transferring information with Rclone or WinSCP. Hunters International deployed Rust-based ransomware against Windows and VMware ESXi environments. Observed variants used AES-256-CTR encryption; ESXi deployment involved VMware PowerCLI, SSH, and coordinated execution across hosts. Recovery-inhibition behavior included deleting shadow copies and backups, disabling recovery settings, and powering off virtual machines. Additional evasion techniques included DLL sideloading, disabling Microsoft Defender, and switching to a DLL ransomware payload after endpoint protection quarantined an executable variant. WorldLeaks maintains a dedicated leak site to pressure victims through threatened or actual disclosure of stolen information. Its encryption-less extortion model is distinct from the encryption-and-data-theft attacks documented under the Hunters International name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE-2017-17215 9.1 NETGEAR Routers (R6400, R7000, R8000) World Leaks, TheGentlemen, Devman Link
Initial access was achieved through the successful exploitation of CVE-2024-55591, an authentication bypass vulnerability affecting FortiOS and FortiProxy.
Other cases include Oracle WebLogic Server CVE-2025-21535, a missing authentication vulnerability tied to initial access in activity attributed to Hunters International...
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Defunct RaaS operation and suspected Hive rebrand that transitioned elements of its operation to World Leaks.
A ransomware/data leak group listed among the top groups by number of incidents.
Referenced as an example of an emerging encryption-less, data theft-only extortion model rather than as a central actor in the report.
Claimed responsibility for breaching Operation PAR’s internal network, stealing confidential information, and threatening public release unless ransom demands were met.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.