Ransomware gang Hunters International has shut up shop and offered decryption keys to all victims as a parting favor. Announcing the news on Thursday morning, the gang deleted all victim data from its dark web leak site and issued a statement confirming its closure.
“We, at Hunters International, wish to inform you of a significant decision regarding our operations,” it said. “After careful consideration and in light of recent developments, we have decided to close the Hunters International project. This decision was not made lightly, and we recognize the impact it has on the organizations we have interacted with.”
Read more…
Source: MSN News
Sign up for the Cyber Security Review Newsletter
The latest news and insights delivered right to your inbox.
Related:
- Attacker combines phone, email lures into believable, complex attack chain
August 10, 2023
In the course of performing a postmortem investigation of an infected computer, Sophos X-Ops discovered that the attack began with an innocent-sounding phone call. The caller prompted an employee of a Switzerland-based organization to initiate a complex attack chain that compromised the employee’s computer. Sophos Incident Response analysts found that the attackers may have targeted the ...
- JanelaRAT: Repurposed BX Rat Variant Targeting LATAM FinTech
August 10, 2023
In June of 2023, researchers at Zscaler ThreatLabz discovered a threat actor targeting FinTech users in the LATAM region. JanelaRAT involves several tactics, techniques, and procedures (TTPs) such as DLL side-loading, dynamic C2 infrastructure, and a multi-stage attack. The final malware involved in this campaign is a heavily modified variant of BX RAT. Because of this, ...
- Common TTPs of attacks against industrial organizations
August 10, 2023
In 2022 Kaspersky investigated a series of attacks against industrial organizations in Eastern Europe. In the campaigns, the attackers aimed to establish a permanent channel for data exfiltration, including data stored on air-gapped systems. Based on similarities found between these campaigns and previously researched campaigns (e.g., ExCone, DexCone), including the use of FourteenHi variants, specific TTPs ...
- An overview of the new Rhysida ransomware targeting the Healthcare sector
August 9, 2023
On August 4, 2023, the HHS’ Health Sector Cybersecurity Coordination Center (HC3) released a security alert about a relatively new ransomware called Rhysida (detected as Ransom.PS1.RHYSIDA.SM), which has been active since May 2023. In this blog entry, Trend Micro reaseachers will provide details on Rhysida, including its targets and what they know about its infection ...
- Attackers Distribute Malware via Freeze.rs And SYK Crypter
August 9, 2023
FortiGuard Labs recently detected a new injector written in Rust—one of the fastest-growing programming languages—to inject shellcode and introduce XWorm into a victim’s environment. While Rust is relatively uncommon in malware development, several campaigns have adopted this language since 2019, including Buer loader, Hive, and RansomExx. FortiGuard Labs analysis also revealed a significant increase in injector ...
- Personal data of at least 26,212 people accessed in ransomware attack, Dallas tells state
August 9, 2023
Computer hackers accessed the personal information of at least 26,212 Texans in the recent ransomware attack on the city of Dallas, according to an official disclosure made public Monday on the Texas attorney general’s web site, three months after the breach. The city’s notice to the attorney general’s office says the data breach included names, addresses, ...

