HackerFeeds
All ransomware groups

hunters

307 tracked victims
·first seen 2021-09-09·last activity 2025-05-27

Group profile

In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold, along with its website and older versions developed in Golang and C (although this purchase has only been reported by the actors without concrete evidence). The buyer of this new source code was the group Hunters International, who claimed to have fixed the bugs in the Ransomware Hive that were responsible for preventing file decryption in some cases. The group also stated that file encryption would not be their primary focus; instead, they would use data theft as a method to pressure victims during extortion attempts.

MITRE ATT&CK TTPs

TA0002

Execution

  • T1106Native API

    The threat actor utilizes the application programming interface to execute malicious behaviors.

  • T1129Shared Modules

    The threat actor executes payloads by loading shared modules.

TA0003

Persistence

  • T1547Boot or Logon Autostart Execution

    The threat actor may set system configurations to automatically execute malware during system startup or login.

TA0005

Defense Evasion

  • T1027Obfuscated Files or Information

    The threat actor utilizes obfuscation on files used for their attack, encrypting, encoding, or obfuscating their content.

  • T1562Impair Defenses

    The actor may maliciously modify victim environment components to hinder or disable defense mechanisms.

TA0007

Discovery

  • T1057Process Discovery

    The threat actor may attempt to gather information about running processes on a system.

  • T1082System Information Discovery

    The actor may try to obtain detailed information about the operating system and hardware, including version, patches, hotfixes, and other details.

  • T1083File and Directory Discovery

    The threat actor may enumerate files and directories or search specific locations on a host or network share for certain information within a file system.

TA0011

Command and Control

  • T1071Application Layer Protocol

    The threat actor can communicate using OSI application layer protocols to avoid network detection/filtering, blending in with existing traffic.

  • T1071.001Application Layer Protocol: Web Protocols

    The threat actor can communicate using web traffic associated application layer protocols to avoid detection.

TA0040

Impact

  • T1486Data Encrypted for Impact

    The threat actor can encrypt data on the target system or on a large number of systems to disrupt system availability.

Recent victims

showing 50 of 307
DateWebsite / victimSectorCountry
2025-05-27Public SectorCO
2025-05-27
wrapandsend.com
Wrap & Send Serviceswrapandsend.com
Consumer ServicesUS
2025-05-27
eight8ate.ph
Eight8Ate Holdings, Incwww.eight8ate.ph
Consumer ServicesPH
2025-05-05ConstructionGB
2025-05-05ManufacturingUS
2025-04-30
telcointercon.com
Telco Intercontinentaltelcointercon.com
TelecommunicationUS
2025-04-30
digestivespecialists.com
Digestive Specialistsdigestivespecialists.com
HealthcareUS
2025-04-30Public SectorES
2025-04-28
mlmins.com
Minnesota Lawyers Mutual Insurancewww.mlmins.com
Financial ServicesUS
2025-04-25Transportation/LogisticsMX
2025-04-25
kasb.com
Kasb Bank - K-Tradewww.kasb.com
Financial ServicesPK
2025-04-23Not FoundAT
2025-04-21HealthcareBE
2025-04-17Not FoundCZ
2025-04-06
groupedelcourt.com
Groupe Delcourtgroupedelcourt.com
Consumer ServicesFR
2025-04-06
hofmann-foerdertechnik.com
Hofmann Fördertechnik GmbHhofmann-foerdertechnik.com
ManufacturingDE
2025-04-06
idsil.com
IDS Infotechidsil.com
TechnologyIN
2025-04-05
nexia.com.cy
Nexia Poyiadjis ITnexia.com.cy
TechnologyCY
2025-01-11ManufacturingCZ
2025-04-05
bmscat.com
Blackmon Mooringbmscat.com
Business ServicesUS
2025-04-04
sansonegroup.com
Sansone Groupsansonegroup.com
Not FoundUS
2025-04-04
nationalsign.net
National Sign corpnationalsign.net
ManufacturingUS
2025-03-20
cargillsbank.com
Cargills Bankcargillsbank.com
Financial ServicesLK
2025-03-20
megacentro.cl
Megacentromegacentro.cl
Consumer ServicesCL
2025-03-17TelecommunicationCA
2025-03-16
courageoushomecare.com
Courageous Home Carecourageoushomecare.com
HealthcareUS
2025-03-11
edesur.com.do
Edesur Dominicanaedesur.com.do
EnergyDO
2025-03-04
tatatechnologies.com
Tata Technologiestatatechnologies.com
TechnologyIN
2025-02-26
kendallautogroup.com
Kendall Auto Groupkendallautogroup.com
Consumer ServicesUS
2025-02-04
omni-united.com
Omni Unitedomni-united.com
ManufacturingSG
2025-02-25
vermeermexico.com
Vermeer Mexicovermeermexico.com
ManufacturingMX
2025-02-11
nichino-ryokka.co.jp
Nichino Ryokka Co Ltdnichino-ryokka.co.jp
Agriculture and Food ProductionJP
2025-02-22Not FoundEG
2025-02-22
ccoo-servicios.es
CCOO Serviciosccoo-servicios.es
Business ServicesES
2025-02-17ManufacturingCH
2021-09-09TelecommunicationCA
2025-02-08
sakai.co.jp
SAKAI SOUKEN Co.sakai.co.jp
ManufacturingJP
2025-02-06
robertshaw.com
Robertshawrobertshaw.com
ManufacturingUS
2025-01-20
pvep.com.vn
PetroVietnam Exploration Production Corporationpvep.com.vn
EnergyVN
2025-01-11
thasegawa.com
T. Hasegawa USAthasegawa.com
ManufacturingUS
2025-01-11
barberspec.com
Barber Specialtiesbarberspec.com
Business ServicesUS
2025-01-11ManufacturingUS
2025-01-11
patriarche.fr
Patriarche Office of Architecturepatriarche.fr
Business ServicesFR
2025-01-11ManufacturingIT
2025-01-11Business ServicesGB
2025-01-11
unisourcejv.com
Unisource Information Servicesunisourcejv.com
TechnologyUS
2025-01-03
n-u.co.jp
Nikki-Universal Co Ltdn-u.co.jp
ManufacturingJP
2024-12-26
famhelp.com
Family Help & Wellnessfamhelp.com
HealthcareUS
2024-12-15
sealandaire.com
SeaLandAire Technologiessealandaire.com
TechnologyUS
2024-10-31
smartlynx.aero
SmartLynx Airlines SIAsmartlynx.aero
Transportation/LogisticsLV