HomeSecurityThe Hunters International team uses the source code and infrastructure of...

Hunters International group uses Hive ransomware source code and infrastructure

A new ransomware called Hunters International has acquired the source code and infrastructure of the Hive ransomware (a now defunct operation) and has launched its own attacks.

Hunters International

“ It appears that the Hive group’s leadership has made the strategic decision to cease operations and transfer its remaining assets to another group, Hunters International ,” Martin Zugec, Bitdefender’s director of technical solutions, said in a report

Hive was once a prolific ransomware-as-a-service (RaaS), but it ceased operations when law enforcement worked together to “dismantle”in January 2023.

See also: LockBit ransomware gang leaked Boeing data

Such crackdowns typically force ransomware gangs to cease operations or regroup under a different name. However, in some cases, they may transfer their source code and remaining infrastructure to another threat.

Reports about Hunters International ransomware as a possible rebranding of Hive emerged last month after several code similarities were identified between the two ransomware.

The hackers behind it, however, tried to dispel these speculations, stating that they purchased Hive's source code and website from its developers.

“This group seems to be more focused on data theft,” Zugec said. The expert explained that all reported victims faced extraction data, but there was no data encryption in some cases. Therefore, we could say that Hunters International is more of an extortion group than a ransomware gang (in the typical sense).

Bitdefender 's analysis of the ransomware sample reveals that it is based on the Rust programming language . Hive ransomware had switched to this programming language in July 2022 due to its resistance to reverse engineering.

See also: Industrial & Commercial Bank of China (ICBC): “Hit” by ransomware

“In general, as the new group adopts this ransomware code, it seems to be aiming for simplification,” Zugec said.

Hackers reduced the number of command line parameters, improved the encryption key storage process, etc.

Hive ransomware source code
Hunters International group uses Hive ransomware source code and infrastructure

The ransomware, in addition to incorporating an exclusion list of file extensions, file names, and directories that should not be encrypted, executes commands to prevent data as well as terminate a series of processes that could potentially affect the process.

“While Hive was one of the most dangerous ransomware groups, it remains to be seen whether Hunters International will prove to be equally or even more formidable,” Zugec noted.

“This group is emerging as a new threat actor starting with a “mature” toolkit and seems eager to show its capabilities“.

See also: Kyocera AVX (KAVX): Ransomware attack led to data breach

The potential impacts and risks associated with this new ransomware group are multiple and serious. First, the use of Hive code and infrastructure by this Hunters International group could lead to an increase in the threat of ransomware attacks in general.

Hive ransomware focused on avoiding detection by security , and the new group may try to improve on it to make it even more effective and resilient. The new ransomware group could achieve more attacks and remain undetected for a longer period of time.

Additionally, the emergence of a new ransomware group that uses Hive’s code and infrastructure could lead to an increase in ransom demands. attacks are typically accompanied by demands for payment to restore data or prevent the disclosure of stolen data. With the emergence of a new group, ransom demands may increase, as the group may find its attacks more effective and harder to detect.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS