World Leaks is a cyber extortion and ransomware group that emerged in 2025 as a rebrand or spin-off of Hunters International, which itself has been widely linked to code and operational lineage from Hive. Reporting consistently characterizes World Leaks as shifting emphasis away from traditional encryption-centric ransomware toward data theft and encryption-less extortion, while still being referred to in many cases as a ransomware operation and maintaining a leak site for coercion. The group has claimed numerous victims globally and has been particularly visible in attacks against organizations in the United States and India. Reported victims and targeting include healthcare providers, manufacturers, educational institutions, and contractors tied to critical infrastructure projects. Publicly discussed incidents include claims involving Operation PAR and Centers Laboratory in the United States, as well as data theft and publication activity affecting Reliance Infrastructure and files associated with India’s Kudankulam Nuclear Power Plant project. Additional reporting notes victim claims involving Tata Electronics, Tata Group, and Nike. World Leaks is associated with large-scale data exfiltration, leak-site publication, and ransom demands backed by threats of public disclosure. In multiple cases, the group publicly posted stolen files after deadlines expired, consistent with data-theft extortion. Some reporting describes the operation as an emerging model of encryption-less extortion that lowers the barrier to conducting industrial-sector attacks. At the same time, victim reporting and incident summaries also continue to label some World Leaks intrusions as ransomware attacks, indicating the brand spans both classic ransomware and theft-first extortion activity. Tradecraft attributed through its Hunters International lineage includes initial access via malvertising and trojanized software installers, use of remote access trojans and persistence mechanisms, credential collection and surveillance, reverse SSH tunneling, RDP-enabled lateral movement, disabling security tooling prior to impact, and use of utilities for staging and exfiltration. Hunters International reporting also links the lineage to custom ESXi ransomware deployment, DLL sideloading, and VMware-focused post-exploitation. Separate reporting associates World Leaks with an in-house exfiltration tool referred to as RustyRocket. The group operates a data leak site and has been described as capable of hosting and publishing large stolen datasets. World Leaks is best understood as a financially motivated extortion operation in the contemporary ransomware ecosystem, notable for its rebranding from Hunters International and its strong emphasis on exfiltration-led coercion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2017-17215 9.1 NETGEAR Routers (R6400, R7000, R8000) World Leaks, TheGentlemen, Devman Link
Other cases include Oracle WebLogic Server CVE-2025-21535, a missing authentication vulnerability tied to initial access in activity attributed to Hunters International...
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of an emerging encryption-less, data theft-only extortion model rather than as a central actor in the report.
Claimed responsibility for breaching Operation PAR’s internal network, stealing confidential information, and threatening public release unless ransom demands were met.
Referenced as a ransomware and extortion group that published allegedly stolen files from contractors tied to India's largest nuclear power project and separately claimed an attack on Tata Electronics with a ransom demand.
An emerging or returning ransomware group identified in the report.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.