ZeroFox Intelligence Flash Report - Hunters International Increases Ransomware Activity
|by Alpha Team

ZeroFox Intelligence Flash Report - Hunters International Increases Ransomware Activity
Product Serial: F-2024-02-26a
TLP:CLEAR
In this flash report, ZeroFox researchers provide updates around a recent increase in Ransomware and Digital Extortion activity from the threat collective Hunters International.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Ransomware and digital extortion (R&DE) collective Hunters International has significantly increased its operational tempo, having so far conducted at least 29 attacks in February 2024.
- Hunters International is a ransomware-as-a-service (RaaS) operation that was first observed in October 2023. Over the following quarter, affiliates leveraged the ransomware against a diverse set of global targets from an array of industries.
- Since Q4 2023, over 60 percent of R&DE attacks leveraging Hunters International ransomware targeted organizations based in North America. The most targeted industries are manufacturing, construction, and healthcare.
Tags: tlp:clear, all industries, DDW Ransomware, threat actor