Hunters
In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold, along with its website and older versions developed in Golang and C (although this purchase has only been reported by the actors without concrete evidence). The buyer of this new source code was the group Hunters International, who claimed to have fixed the bugs in the Ransomware Hive that were responsible for preventing file decryption in some cases. The group also stated that file encryption would not be their primary focus; instead, they would use data theft as a method to pressure victims during extortion attempts.
Niveau de menace
ÉLEVÉ
Tactiques, techniques et procédures (TTP)
DiscoveryEnum
- Advanced IP Scanner
- Advanced Port Scanner
Exfiltration
- RClone
- WinSCP
Infrastructure connue
Les services cachés Tor suivants ont été associés à ce groupe :
HUNTERS INTERNATIONALHUNTERS INTERNATIONALHUNTERS INTERNATIONALAttention Required! | Cloudflare
Attention : ces sites sont malveillants. Ne les visitez pas sans mesures de sécurité adaptées.
Vérifier si vous êtes touché
Cherchez dans notre base si votre organisation figure sur la liste des victimes de Hunters.
score de risque · catégories de menace · sources · ancienneté · confiance — en une requête