hunters

Ransomware
Sourceransomware.live

About the group

In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold, along with its website and older versions developed in Golang and C (although this purchase has only been reported by the actors without concrete evidence). The buyer of this new source code was the group Hunters International, who claimed to have fixed the bugs in the Ransomware Hive that were responsible for preventing file decryption in some cases. The group also stated that file encryption would not be their primary focus; instead, they would use data theft as a method to pressure victims during extortion attempts.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group hunters has 4 known ransomware victims. See the most affected sectors and countries and recent victims.

4known victims
4in Brazil
3sectors hit
Most attacked sectors
Energy & Utilities2
Manufacturing1
Transportation1
Most affected countries
🇧🇷 Brasil4
Recent victims
Aeris EnergyEnergy & Utilities · BR · 2024-11-23
Toyota BrazilManufacturing · BR · 2024-04-13
Tiete AutomobileTransportation · BR · 2024-02-17
Alupar Investimento SAEnergy & Utilities · BR · 2024-01-19

hunters uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →