One of the most dangerous ransomware kits around might have just gotten a rebrand

Ransomware
Image Credit: Shutterstock (Image credit: Shutterstock)

There is a good chance that one of the world’s most dangerous ransomware operators out there - Hive - has just gotten a rebrand.

Earlier this month, security researchers spotted a new player in the ransomware game, called Hunters International. The group doesn’t focus on encrypting their victims’ endpoints as much as it focuses on data theft and so far, it only managed to compromise one victim- a UK school.

However, the group’s encryptor is strikingly similar to that of Hive. More than 60% of the code overlaps with that of Hive ransomware, researchers said, with some going so far as to pinpoint the exact version of Hive that was rebranded - version 6.

Dismantled by the FBI

Hunters International, though, is having none of it. The group claims to have bought not just the encryptor source code, but also the website and old Golang and C version. The group also claims Hive’s encryptor came with a few bugs that it fixed.

If both groups were active at the same time, then it would clear any confusion as to whether they were the same or different operators. As things stand now, that most likely won’t happen, as Hive’s operations were terminated after its Tor payment and data leak site were confiscated by law enforcement early this year. 

Hive had 250 affiliates, BleepingComputer further stated, allowing the FBI to infiltrate the network and keep a low profile for half a year, gathering intelligence and mapping the group out. Before the seizure, Hive breached more than 1,300 companies and extorted more than $100 million from its victims. 

FBI’s work resulted in a decryption key that was handed out to more than 1,300 victims. 

In order to avoid being targeted by the police, most ransomware groups these days refrain from attacking critical infrastructure organizations, state organizations, or healthcare institutions.

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
ransomware avast
“Every organization is vulnerable” - ransomware dominates security threats in 2024, so how can your business stay safe?
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
Illustration of a laptop with a magnifying glass exposing a beetle on-screen
This devious macOS malware is evading capture by using Apple's own encryption
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge benchmark leak has eased my worries about its performance
Gmail at 20
Your Gmail search results are about to get a huge change - and I'm not sure you're going to be happy with it
Google Pixel 9 in green Wintergreen color showing AI features on screen
Older Pixels just got a big performance boost, while the Pixel 9a is lacking a key feature
Wonka poster
Netflix cooks up sweet new reality TV series based on Charlie and the Chocolate Factory, and it's a dream come true for me
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can