Ransomware crew Hunters International shuts down, hands out keys to victims


Ransomware gang Hunters International has shut up shop and offered decryption keys to all victims as a parting favor. Announcing the news on Thursday morning, the gang deleted all victim data from its dark web leak site and issued a statement confirming its closure.

“We, at Hunters International, wish to inform you of a significant decision regarding our operations,” it said. “After careful consideration and in light of recent developments, we have decided to close the Hunters International project. This decision was not made lightly, and we recognize the impact it has on the organizations we have interacted with.”

Read more…
Source: MSN News


Sign up for the Cyber Security Review Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Labour Party says it has been hit by ‘large-scale cyber attack’

    November 12, 2019

    Labour says it has been hit by a “sophisticated and large-scale cyber attack” on its digital platforms. A party spokeswoman said the cyber attack “failed” because of their “robust security systems” and that she was confident no data breach occurred. “Security procedures have slowed down some of our campaign activities, but these were restored this morning and we ...

  • Emotet resurgence packs in new binaries, Trickbot functions

    November 6, 2019

    Emotet, a Banking Trojan turned devastating modular threat, has returned with upgraded functions in a new wave of attacks. The malware, first discovered in 2014, has evolved over the past few years from a relatively basic, singular threat into a customizable modular package used to deploy additional payloads against financial institutions, the enterprise, and consumers worldwide. Emotet, believed to ...

  • Buran Ransomware; the Evolution of VegaLocker

    November 5, 2019

    McAfee’s Advanced Threat Research Team observed how a new ransomware family named ‘Buran’ appeared in May 2019. Buran works as a RaaS model like other ransomware families such as REVil, GandCrab (now defunct), Phobos, etc. The author(s) take 25% of the income earned by affiliates, instead of the 30% – 40%, numbers from notorious malware families ...

  • Canadian Nunavut government systems crippled by ransomware

    November 5, 2019

    Canadian government IT systems have been forced into lockdown after a successful ransomware attack. On Monday, government officials for the Nunavut region said that over the weekend, a “new and sophisticated type of ransomware” struck the territory. All government services — with the exception of an energy corporation — that rely on access to electronic information stored ...

  • Wizard Spider Upgrades Ryuk Ransomware to Reach Deep into LANs

    November 4, 2019

    The Ryuk ransomware has added two features to enhance its effectiveness: The ability to target systems that are in “standby” or sleep mode; and the use of Address Resolution Protocol (ARP) pinging to find drives on a company’s LAN. Both are employed after the initial network compromise of a victim organization. Ryuk, which is distributed by ...

  • Nemty Ransomware Expands Its Reach, Also Delivered by Trik Botnet

    November 4, 2019

    The Nemty ransomware (Ransom.Nemty), initially detected in August 2019, has increased its reach by partnering up with the Trik botnet (Trojan.Wortrik), which now delivers Nemty to compromised computers. Trik, also known as Phorpiex, has been around for approximately 10 years. In its early days, the malware self-propagated via removable USB drives, Windows Live Messenger, or Skype ...