TechCrunch - HealthTech 20小时前
Ransomware gang Hunters International says it’s shutting down
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Hunters International,一个臭名昭著的勒索软件团伙,在暗网页面上宣布关闭。该团伙表示,经过深思熟虑,并考虑到最近的事态发展,决定关闭该项目。他们还承诺向所有受其勒索软件影响的公司提供免费解密密钥,以帮助受害者恢复加密数据。虽然关闭的具体原因尚不明确,但网络安全公司Recorded Future的威胁情报分析师Allan Liska认为,这可能是为了与旧的基础设施“切割关系”,并可能转型为一个名为World Leaks的新组织。Hunters International 成立两年以来,曾对包括美国癌症中心和美国法警局在内的多个机构发起攻击。

🛡️ Hunters International 在暗网页面上宣布关闭,并表示已决定关闭该勒索软件项目,但未具体说明原因。

🔑 该团伙承诺向所有受其勒索软件影响的公司提供免费解密密钥,以帮助受害者恢复加密数据,并表示希望受害者无需支付赎金。

🔄 根据网络安全公司Recorded Future的分析师Allan Liska的说法,关闭可能是为了“切割”与旧基础设施的联系,并可能转型为名为World Leaks的新组织。

🕵️‍♂️ Liska 认为,使用相同的技术基础设施太久会增加被执法部门发现的风险,这可能是Hunters International关闭的原因之一,也可能是他们预感到了执法部门的行动。

💰 一些勒索软件团伙在获得足够的资金后会选择关闭,或者为了逃避制裁而改头换面,但Hunters International关闭的具体动机尚不清楚。

The ransomware gang known as Hunters International announced on its dark web page Thursday that it is shutting down. 

“After careful consideration and in light of recent developments, we have decided to close the Hunters International project,” the hackers wrote in a post, without clarifying what specific developments it was referring to. “This decision was not made lightly, and we recognize the impact it has on the organizations we have interacted with.”

The hackers also said they are offering free decryption keys “to all companies that have been impacted by our ransomware.”

“Our goal is to ensure that you can recover your encrypted data without the burden of paying ransoms,” wrote the gang, which asked victims to visit its official site to obtain the decryption keys and to recover the encrypted files.

At the time of writing, there is no such information on the website. 

Hunters International has claimed several victims in its two years of existence, including a U.S. cancer center, and the U.S. Marshals Service; although, the law enforcement agency denied having been hacked by the cybercrime gang.

The hunters international post announcing it is shutting down. (Image: Techcrunch)

Several ransomware gangs in the past have released their victims’ decryption keys then shut down, each of them for different reasons. Some shut down only to return under a new name, perhaps in an attempt to confuse researchers and law enforcement agencies, and sometimes to escape sanctions. Others decided to call it quits after obtaining enough funds to retire.

Techcrunch event

Boston, MA | July 15

REGISTER NOW

In the case of Hunters International, it’s still too early to tell what the gang’s motivations are for shutting down, but there were signs as far back as April that point to a rebrand and transition to a group called World Leaks, according to Allan Liska, a threat intelligence analyst at cybersecurity firm Recorded Future. 

“I think this is more of a ‘cutting of ties’ with the old infrastructure,” said Liska, who has been tracking ransomware for years. “As far as releasing decryption keys, at this point they aren’t likely to make any money from any Hunters’ victims who are still out there, so they probably see it as a gesture that doesn’t really cost them anything.”

World Leaks group uses a new ransomware software and has a new site hosted elsewhere, but the people behind it may be the same, said Liska.

Liska said the reason for the gang going dark may be that “using the same technical infrastructure too long makes you more vulnerable to law enforcement,” referring to Hive, a ransomware gang that was seized and shut down by the FBI in 2023. 

“Or, they got wind that law enforcement was closing in and decided to get ahead of them,” he said.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Hunters International 勒索软件 网络安全 World Leaks 解密密钥
相关文章