Hunters International
World Leaks is a cyber extortion operation and Extortion-as-a-Service (EaaS) group that steals sensitive data from victim organizations and threatens to publish it on dark web leak infrastructure if ransom demands are not paid. The group is described in the content as a rebrand or splinter of Hunters International, with reporting placing its emergence in early 2025 or January 2025; some cited reporting also describes it as emerging in early 2024 and shifting in mid-2025 to an extortion-only model. Known aliases in the provided content are Hunters International, worldleaks, and world_leaks. The content consistently describes World Leaks as focusing primarily on data theft and extortion rather than file encryption, although one cited Darktrace case attributed to World Leaks in a healthcare environment involved both exfiltration and encryption, indicating affiliates may deviate from the group’s claimed extortion-only model. The group operates a dark web leak site and a victim negotiation portal with live chat, and some reporting says it also maintains an affiliate management panel and an "insider" platform intended to give journalists early access to stolen data to increase pressure on victims. Reported targeting spans healthcare, manufacturing, technology, government, media, telecommunications, energy, utilities, information technology, and defense-adjacent organizations. The content states that most identified victims are in the United States, with additional victims in Canada, Europe, India, and China. Victims and claimed victims mentioned in the content include Nike, Dell, UBS, Mediaworks, Legend Senior Living, the City of Los Angeles, and LAPD-related data exposed through a Los Angeles City Attorney’s Office third-party storage/discovery transfer system. Initial access methods attributed to World Leaks in the provided reporting include phishing, compromised credentials, valid VPN credentials, exploitation of exposed or public-facing services, RDP abuse, and brute force against exposed RDP. Reported operational tradecraft includes data discovery and exfiltration; use of SMB, RDP, SSH, PsExec, WinRM, and account manipulation; persistence via registry modifications and scheduled tasks; and exfiltration via custom tooling, Rclone, WinSCP as a fallback, MEGA, Backblaze, HTTPS, TOR, and Cloudflare-backed infrastructure. One intrusion described in detail involved brute forcing an exposed RDP service, disabling security controls with privacy.sexy, reconnaissance with SoftPerfect Network Scanner, use of a Cobalt Strike PowerShell stager, deployment of lactenin.exe, and use of RustyRocket (agent.exe), described as a custom World Leaks exfiltration platform, to collect files over SMB and exfiltrate them over HTTPS to thousands of Cloudflare IPs. That intrusion also involved tailored extortion notes for leadership and employees and use of Tor-based negotiation infrastructure. The content also notes overlap or association in reporting with Hive, Secp0 Ransomware, and UNC6148, but only as stated associations in the source material. Sub-groups are not directly identified in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- retail
Tradecraft
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2017-17215 9.1 NETGEAR Routers (R6400, R7000, R8000) World Leaks, TheGentlemen, Devman Link
Other cases include Oracle WebLogic Server CVE-2025-21535, a missing authentication vulnerability tied to initial access in activity attributed to Hunters International...
Observables
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the prior ransomware operation from which World Leaks rebranded.
Leading ransomware actor targeting high-value Chinese sectors in a competitive ransomware landscape.
Claimed responsibility for the Legend Senior Living attack, listed the victim on its dark web leak site, and leaked stolen data after ransom was not paid.
Ransomware intrusion activity using Rclone as the primary exfiltration tool and WinSCP as a fallback when cloud sync protocols are blocked.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.