One of the biggest ransomware gangs around is shutting down - but is it for good?
Date:
Fri, 04 Jul 2025 09:57:00 +0000
Description:
Hunters International says it's quitting ransomware for good - but not everyone believes them.
FULL STORY ======================================================================Hunters International struck many private and public entities, including Tata and Telecom Namibia The group says it is disbanding "in light of recent events"
It even released decryption keys for their victims
A major ransomware operation has announced a complete shutdown and the public release of decryption keys - however, some are skeptical that this is the
last weve seen of this particular group.
The operators, known as Hunters International, published a short announcement on their dark web site, notifying their followers, affiliates, and the wider cybercriminal community, that they will no longer operate.
After careful consideration and in light of recent developments, we have decided to close the Hunters International project, the announcement reads. This decision was not made lightly, and we recognize the impact it has on the organizations we have interacted with.
Get 55% off Incogni's Data Removal service with code TECHRADAR
Wipe your personal data off the internet with the Incogni data removal service. Stop identity thieves
and protect your privacy from unwanted spam and scam calls. View Deal
Callback phishing
While the group mentions recent developments, it doesnt elaborate, so we dont know if this means they were seized by law enforcement, or they simply extorted enough money to call it quits.
TechCrunch , on the other hand, believes there could be a third option - a smoke-and-mirrors effort to throw the police off. Discussing the matter with threat intelligence analyst from Recorded Future, Allan Liska, TechCrunch learned the group might be rebranding to World Leaks.
I think this is more of a cutting of ties with the old infrastructure, Liska told the publication. This wouldnt be the first group that rebranded to try and hide their tracks.
After the Colonial Pipeline attack, DarkSide, rebranded into BlackMatter, and later Alphv/BlackCat, and REvil (Sodinokibi) was preceded by GandCrab.
As for releasing decryption keys, while commendable, it doesnt mean much for the attackers, Liska argues. These are mostly older victims who had no intention of paying anyway, so for the group - nothing was lost.
As far as releasing decryption keys, at this point they arent likely to make any money from any Hunters victims who are still out there, so they probably see it as a gesture that doesnt really cost them anything, Liska concluded. You might also like America is the top source of spam, and its getting worse thanks to growing data center infrastructure Take a look at our guide to the best authenticator app We've rounded up the best password managers
======================================================================
Link to news story:
https://www.techradar.com/pro/security/one-of-the-biggest-ransomware-gangs-aro und-is-shutting-down-but-is-it-for-good
--- Mystic BBS v1.12 A47 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)