Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors worldleaks

Description

Worldleaks emerged in January 2025 as a rebranding effort by the previously known Hunters International ransomware operation. Rather than employing their original encryption‑based extortion model, the group now prioritizes data theft and blackmail: they infiltrate target networks, exfiltrate valuable documents and personal information, and then demand payment under threat of publication. The attackers leverage a blend of social engineering and credential abuse to gain initial access. Once inside, they establish persistence via custom backdoor implants and gather sensitive files through automated scans or manual selection. The stolen data is usually uploaded to staging servers controlled by the actor before a ransom note is delivered. Their operational tempo is rapid; many victims report simultaneous infiltration and exfiltration within days of initial compromise. This high‑volume approach indicates extensive reuse of templates, shared infrastructure, and potential automation tools common among criminal ransomware affiliates.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Worldleaks is a medium‑sophistication criminal group that rebranded from the Hunters International ransomware gang in January 2025. The group has shifted its focus from encrypting files to exfiltrating sensitive data and threatening to release it unless a ransom is paid, targeting a wide array of sectors across the United States and other regions. Since its emergence they have compromised more than 150 victims worldwide, demonstrating an aggressive opportunistic threat profile.

Goals & Targeting

The primary motivation for Worldleaks remains financial gain through extortion. By targeting organizations that hold high‑value confidential information—such as legal documents, patient medical records, intellectual property, and personal data—they can leverage the perceived risk of public disclosure to secure ransom payments or monetize the data on underground markets. The group’s victim list includes a diverse cross‐section of sectors including law firms, healthcare providers, educational institutions, municipal governments, hotels, manufacturing companies, and small businesses in multiple countries.

Enhanced Description

Key Capabilities

  • Spear‑phishing with macro‑laden Office documents or malicious links
  • Credential theft via phishing or compromised third‑party services
  • Lateral movement using valid accounts and pass‑the‑hash techniques
  • Custom backdoor/Remote Access Trojan for persistence
  • Automated data collection scripts that harvest files of interest
  • Exfiltration over HTTPS to staging servers controlled by the attacker
  • C2 communications over standard web protocols with domain fronting
  • Use of bulletproof or compromised hosting to host exfiltration endpoints

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1193: Spearphishing Attachment
T1192: Spearphishing Link
T1064: Scripting
T1059.003: PowerShell
T1078: Valid Accounts
T1105: Ingress Tool Transfer
T1041: Exfiltration Over Command and Control Channel
T1015: Software Discovery
T1021.001: Remote Services: SMB

Software / Tooling

Custom RAT backdoor
PowerShell-based script implants

Campaigns & Victims

Worldleaks runs on a high‑volume, opportunistic model. Victims have been identified across many industry verticals with little evidence of pre‑targeting by niche sector knowledge—suggesting either data broker access or widespread vulnerability exploitation. The group typically deploys initial compromise via spear‑phishing attachments or suspicious email links, then establishes a staging server to receive exfiltrated files before delivering a ransom note. While the exact infrastructure remains unknown, there is evidence of repeated use of short‑lived domain names for C2 and data host functions in past incidents, indicating reliance on fast‑flux style bulletproof hosting.

IOC Patterns

  • Spear-phishing emails with macro-laden Office documents
  • Malicious download links hosted on compromised third‑party sites
  • Staging infrastructure using rapidly changing domain names
  • Exfiltration of files over HTTPS to attacker-controlled endpoints

Recommended Actions

  • Implement comprehensive phishing awareness training and simulated attacks.
  • Enforce multi‑factor authentication for all privileged accounts.
  • Conduct regular patching cycles, especially for exposed SMB shares and remote services.
  • Deploy network segmentation and strict egress filtering to block unauthorized outbound traffic.
  • Utilize data loss prevention (DLP) tools to detect exfiltration attempts.
  • Maintain up‑to‑date backups stored offline or in immutable storage.
  • Periodically scan internal networks for malicious implants and unusual backdoor activity.

Suggested Tags

APT
criminal
data-exfiltration
blackmail
ransomware rebrand
financial-extortion

Confidence Assessment

The information is derived primarily from limited internal descriptions of Worldleaks and an extensive victim list; no external public advisories or technical reports were found in the collected web research. Consequently, details about specific tools, infrastructure, and precise ATT&CK mapping rely on standard inference from comparable organizations. Confidence in the basic profile (motivation, operational focus) is high, whereas certainty regarding individual tactics, techniques, and tool usage is moderate to low.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

9

Techniques

2

Tools

52

Campaigns

1

IOCs

0

Observed Data

1

Tactics

Tags

Ransomware
Data Exfiltration
ransomware
espionage
financial-gain
municipal-targeting
healthcare-sector
education-sector
manufacturing-sector
cyber- extortion
APT
criminal
data-exfiltration
blackmail
ransomware rebrand
financial-extortion

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Jun 23, 2022
Last Seen
Jul 21, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.