Ransomware Intelligence

worldleaks

Ransomware group profile

124Victims
72Impact score
Also Known As
Hunters International

Description

WorldLeaks is a cyber threat group that emerged in January 2025 as a rebranding of Hunters International, focusing on a pure data extortion model instead of traditional ransomware. They have developed a comprehensive Extortion-as-a-Service (EaaS) platform that aids affiliates in data theft, adopting sophisticated techniques to evade detection and exert pressure on victims through reputational damage.

Key insights

  • WorldLeaks operates primarily through the exploitation of compromised VPN credentials lacking Multi-Factor Authentication (MFA).
  • The group has a unique four-platform infrastructure, which includes a data leak site and a victim negotiation portal.
  • They utilize living-off-the-land techniques and process injection to evade detection.
  • A notable method for initial access is the deployment of a custom rootkit called OVERSTEP on SonicWall SMA appliances.
  • Although primarily focused on data extortion, there are reports of encryption being used in some attacks.
  • WorldLeaks leverages a journalist portal to amplify reputational damage against victims, increasing pressure for compliance.
  • Their extortion model combines financial demands with threats of public data leaks to coerce victim organizations.

Threat Level & Status Breakdown

For worldleaks · Based on incidents in selected period

3threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality4/ 10

Status Breakdown

Claimed100.0%124
First seenJun 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for worldleaks in the selected period

124Total attacks
17peak in Jul
9.5avg / month
JunJulAugSepOctNovDecJanFebMarAprMayJun05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for worldleaks

  1. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
  2. c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for worldleaks

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1021

T1021

T1562

T1562

T1059

T1059

T1047

T1047

T1021.001

T1021.001

T1566.001

T1566.001

T1190

T1190

T1071.002

T1071.002

T1075

T1075

Victims(124)

CompanyDomainCountryIndustryStatusDiscovered
Reliance Groupreliancegroupindia.comIN IndiaFinancial Services
Claimed
9 days ago
Tata Electronicstataelectronics.comIN IndiaManufacturing
Claimed
10 days ago
First Federal Savings & Loanfirstwithus.comUS United StatesFinancial Services
Claimed
10 days ago
Centra Sota Cooperativecentrasota.comUS United StatesOther
Claimed
10 days ago
M1xchangem1xchange.comIN IndiaTechnology
Claimed
10 days ago
Apollo Pipesapollopipes.comIN IndiaManufacturing
Claimed
10 days ago
GDL Transportgdl.seSE SwedenTransportation
Claimed
10 days ago
Access Dentalaccessdentalclinics.comUS United StatesHealthcare
Claimed
14 days ago
United Auto Supplyunitedautosupply.comUS United StatesManufacturing
Claimed
15 days ago
CH Karnchang Publicch-karnchang.co.thTH ThailandOther
Claimed
15 days ago
American Battery Factoryamericanbatteryfactory.comUS United StatesManufacturing
Claimed
22 days ago
BMJ Paperpackbmjpaperpack.comID IndonesiaManufacturing
Claimed
28 days ago
Bestat Pharmaservices Corp.bestat.com.twTW TaiwanHealthcare
Claimed
about 1 month ago
Peyton Law Firmpeytonlaw.comUS United StatesProfessional Services
Claimed
about 2 months ago
Ceywater Consultantsceywater.comLK Sri LankaProfessional Services
Claimed
about 2 months ago
SMTA Sherwood Mutual Telephone Associationsmta.ccUS United StatesTechnology
Claimed
about 2 months ago
Mediaworks KftHU HungaryProfessional Services
Claimed
about 2 months ago
DIME DistribuidoraBR BrazilRetail & E-Commerce
Claimed
about 2 months ago
Carma PackagingIN IndiaManufacturing
Claimed
about 2 months ago
IntikomID IndonesiaTechnology
Claimed
about 2 months ago

Page 1 of 7