Hunters International is a Rust-based ransomware family associated with a financially motivated ransomware-as-a-service operation first publicly identified in 2023. Its encryptor shares code with Hive, and its operators stated that they acquired Hive's source code while denying that they were the same operation. Hunters International has targeted organizations of varying sizes, including healthcare, retail, and construction businesses. Storm-0501 is among the affiliates known to have deployed it.
The family includes Windows executable and DLL variants and a dedicated VMware ESXi encryptor. An analyzed Windows DLL variant performs multithreaded, partial-file encryption using AES-256 in CTR mode with independently generated per-file keys and counters. It can terminate selected processes to release file handles, stop the Volume Shadow Copy Service, delete shadow copies and backup data, and disable recovery options. When supplied with administrator credentials, it can authenticate and impersonate the specified account. Some variants neither append extensions to encrypted files nor leave ransom notes.
The ESXi variant targets VMware configuration, disk, memory, and snapshot files. It can power off virtual machines before encryption, delay execution until a specified time, and fill free datastore space with random data. It uses AES-256-CTR encryption and appends RSA-encrypted metadata to affected files. Its strings are obfuscated.
Associated intrusions have begun through exploitation of CVE-2024-55591 in Fortinet products or malvertising promoting a trojanized RVTools installer that delivers the SMOKEDHAM backdoor. Affiliates have used RDP and reverse SSH tunnels for lateral movement, WinSCP and Rclone for data theft, and VMware PowerCLI with SSH to distribute the ESXi encryptor. These intrusion activities are distinct from the encryptor's built-in functionality. The operation used double extortion through threats to publish stolen information and also conducted exfiltration-only extortion. Hunters International shut down its ransomware operation in July 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Following data exfiltration, threat actors attempted to deploy the exe version “encrypter_windows_x64.exe” of the Hunters International Ransomware, however it was detected and quarantined by EDR, causing the group to pivot and deploy the dll version “encrypter_windows_x64.dll” instead.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following data exfiltration, threat actors attempted to deploy the exe version “encrypter_windows_x64.exe” of the Hunters International Ransomware, however it was detected and quarantined by EDR, causing the group to pivot and deploy the dll version “encrypter_windows_x64.dll” instead.
Our analysis also closely resembles what researchers from Synacktiv observed back in March 2025, in a ransomware case delivering Hunters International.
Le CSIRT de Synacktiv a observé une compromission impliquant un ransomware ESXi de Hunters International, une nouvelle variante apparue après l'été 2024.
For example, a U.S.-based commercial construction contractor allegedly breached in early June 2025 had previously been victimized by GOLD CRESCENT’s Hunters International ransomware in October 2024 and by Payout Kings in June 2025.
...delivering various ransomware payloads over the years, including Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo ransomware.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A now-shuttered RaaS operation suspected to be a Hive rebrand. Its operations transitioned in part to the encryption-free World Leaks extortion brand.
Former ransomware group described as the predecessor/spin-off origin for WorldLeaks. The article notes it exited and offered free decryption keys in July 2025.
Ransomware associated in this content with RDP-based lateral movement.
Referenced as the ransomware manually deployed against ESXi in a historical comparison case that also used SmokedHam, malicious RVTools installers, reverse SSH tunnels, employee-monitoring software, and data-exfiltration utilities. The report suspects a historical UNC2465 affiliation; Hunters International was not the encryptor deployed in the current Qilin incident.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.