Ransomware Intelligence

worldleaks

Ransomware group profile

124Victims
66Impact score
Also Known As
Hunters International

Description

WorldLeaks is a cyber threat group that emerged in January 2025 as a rebranding of Hunters International, focusing on a pure data extortion model instead of traditional ransomware. They have developed a comprehensive Extortion-as-a-Service (EaaS) platform that aids affiliates in data theft, adopting sophisticated techniques to evade detection and exert pressure on victims through reputational damage.

Key insights

  • WorldLeaks operates primarily through the exploitation of compromised VPN credentials lacking Multi-Factor Authentication (MFA).
  • The group has a unique four-platform infrastructure, which includes a data leak site and a victim negotiation portal.
  • They utilize living-off-the-land techniques and process injection to evade detection.
  • A notable method for initial access is the deployment of a custom rootkit called OVERSTEP on SonicWall SMA appliances.
  • Although primarily focused on data extortion, there are reports of encryption being used in some attacks.
  • WorldLeaks leverages a journalist portal to amplify reputational damage against victims, increasing pressure for compliance.
  • Their extortion model combines financial demands with threats of public data leaks to coerce victim organizations.

Threat Level & Status Breakdown

For worldleaks · Based on incidents in selected period

3.4threat level
Aggressiveness6/ 10
Lethality0/ 10
Criticality4.3/ 10

Status Breakdown

Claimed100.0%124
First seenJun 2025
Last seenMay 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for worldleaks in the selected period

124Total attacks
20peak in Jun
10.3avg / month
↓ 15 vs first month
JunJulAugSepOctNovDecJanFebMarAprMay05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for worldleaks

  1. d520d06d78afcad2e03842cb8db4622d18b92739e89dfb8dadf5743f30dcd903
  2. e75e5778e71e062ce4a7af673f0b2513854d2367fee0f01a26c0c998863bdf6e
  3. eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577
  4. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for worldleaks

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1059

T1059

T1047

T1047

T1021.001

T1021.001

T1566.001

T1566.001

T1190

T1190

T1071.002

T1071.002

T1075

T1075

Victims(124)

CompanyDomainCountryIndustryStatusDiscovered
American Battery Factoryamericanbatteryfactory.comUS United StatesManufacturing
Claimed
6 days ago
BMJ Paperpackbmjpaperpack.comID IndonesiaManufacturing
Claimed
12 days ago
Bestat Pharmaservices Corp.bestat.com.twTW TaiwanHealthcare
Claimed
22 days ago
Ceywater Consultantsceywater.comLK Sri LankaProfessional Services
Claimed
about 1 month ago
Peyton Law Firmpeytonlaw.comUS United StatesProfessional Services
Claimed
about 1 month ago
SMTA Sherwood Mutual Telephone Associationsmta.ccUS United StatesTechnology
Claimed
about 1 month ago
Mediaworks KftHU HungaryProfessional Services
Claimed
about 1 month ago
DIME DistribuidoraBR BrazilRetail & E-Commerce
Claimed
about 1 month ago
Carma PackagingIN IndiaManufacturing
Claimed
about 1 month ago
IntikomID IndonesiaTechnology
Claimed
about 1 month ago
Birtcher Anderson & DavisUS United StatesProfessional Services
Claimed
about 1 month ago
Virginia Health ServicesUS United StatesHealthcare
Claimed
about 1 month ago
Equatorial Coca-Cola BottlingMA MoroccoRetail & E-Commerce
Claimed
about 1 month ago
Jersey Fabrication Group LLCUS United StatesManufacturing
Claimed
about 2 months ago
Deaconess Health SystemUS United StatesHealthcare
Claimed
about 2 months ago
National Aerospace FastenersTW TaiwanManufacturing
Claimed
2 months ago
AMBAU PersonalserviceDE GermanyProfessional Services
Claimed
2 months ago
Alamo Heights School DistrictUS United StatesEducation
Claimed
2 months ago
San Felipe Del Rio CISD SchoolUS United StatesEducation
Claimed
2 months ago
Sheraton HotelUS United StatesHospitality
Claimed
2 months ago

Page 1 of 7