World Leaks, also known as WorldLeaks and world_leaks, is a financially motivated cyber-extortion operation that emerged in 2025 as a rebrand or successor of the Hunters International ransomware operation. Hunters International was widely assessed as connected to, or using code derived from, the dismantled Hive ransomware operation. World Leaks principally employs encryption-less data-theft extortion: it claims to steal victim data, pressures victims to pay, and publishes material through a leak site when demands are not met. Its publicly claimed victim activity has included organizations in the United States and India, including healthcare, manufacturing, education, and critical-infrastructure-related entities. In 2026, World Leaks claimed responsibility for breaches involving Reliance Infrastructure material associated with India’s Kudankulam Nuclear Power Plant project; affected parties confirmed a partial breach, while the scope and authenticity of all published data and the intrusion vector were not publicly verified. World Leaks has remained an active, high-volume extortion brand following Hunters International’s shutdown in July 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
CVE-2017-17215 9.1 NETGEAR Routers (R6400, R7000, R8000) World Leaks, TheGentlemen, Devman Link
Other cases include Oracle WebLogic Server CVE-2025-21535, a missing authentication vulnerability tied to initial access in activity attributed to Hunters International...
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Defunct RaaS operation and suspected Hive rebrand that transitioned elements of its operation to World Leaks.
A ransomware/data leak group listed among the top groups by number of incidents.
Referenced as an example of an emerging encryption-less, data theft-only extortion model rather than as a central actor in the report.
Claimed responsibility for breaching Operation PAR’s internal network, stealing confidential information, and threatening public release unless ransom demands were met.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.