Back to blog

Blog Post

Hunters International Shuts Down and Offers Free Decryptors

Share on social

Jul 11, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Hunters International Shuts Down and Offers Free Decryptors

[Hunters International Shutdown]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

The Hunters International ransomware-as-a-service (RaaS) operation has officially shut down, the group announced via its dark web leak site. In a surprising move, the threat actors are now offering free decryptors to help past victims recover their data without paying a ransom.

"After careful consideration and in light of recent developments, we have decided to close the Hunters International project. This decision was not made lightly, and we recognize the impact it has on the organizations we have interacted with," the cybercrime gang says in a statement published on its dark web site.

"As a gesture of goodwill and to assist those affected by our previous activities, we are offering free decryption software to all companies that have been impacted by our ransomware. Our goal is to ensure that you can recover your encrypted data without the burden of paying ransoms."

The group did not elaborate on the “recent developments” that triggered the shutdown, though it followed a November 2024 warning that increased law enforcement scrutiny and declining profits were threatening its future. Although profits were declining, just last year Hunters International was listed as one of the top five malicious ransomware groups last in our annual report. In April, it was also revealed that the group had rebranded and launched a new extortion-only operation under the name World Leaks, dropping encryption tactics in favor of data theft.

Originally surfacing in late 2023, Hunters International was suspected of being a rebrand of the dismantled Hive ransomware group, due to code similarities. It built a reputation for attacking a broad range of platforms - including Windows, Linux, FreeBSD, SunOS, and VMware ESXi, with ransomware supporting x64, x86, and ARM systems.

Over its two year lifespan, the group claimed nearly 300 attacks globally, with ransom demands reaching millions. High-profile victims included the US Marshals Service, Tata Technologies, Hoya, Austal USA, AutoCanada, and the Fred Hutch Cancer Center.

Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient