Ransomware family
World Leaks Ransomware Decryption & Data Recovery
- Inactive
- High
- No public decryptor
World Leaks is the extortion-only brand Hunters International adopted in January 2025: no encryptor, no renamed files, just data theft backed by a Tor leak site. No new victims have been posted since late July 2026 and the leak site has been unreachable, so the operation currently looks dormant.
- First seen
- 2025-01
- File extensions
- No public information
- Ransom notes
- No public information
- Affected platforms
- Windows / Linux
Family profile
- File extensions
- No public information
- Ransom notes
- No public information
- Contact patterns
- Tor leak site on a .onion address beginning with worldleaks
- Per-victim negotiation portal, with credentials handed over separately by the operators
- Direct mail to executives, legal and compliance leads rather than a text file dropped on servers
- Countdown timers, claimed data volumes and staged sample packs on the leak site
- No decryption-related contact of any kind (this group does not encrypt files)
- Aliases / versions
- WorldLeaks、World Leaks DLS
- First seen
- 2025-01
- Status
- Inactive
- Operational status
- Currently dormant
- Threat level
- High
- Affected platforms
- Windows
- Linux
- Tags
- Extortion-only
- Rebranded
- Exploits vulnerabilities
- Formerly
- Hunters International
Decryption does not apply here. World Leaks deploys no encryptor. Files are not renamed and keep opening normally, so there is neither a decryptor nor any need for one. That is exactly why the brand appears in no No More Ransom listing and in no vendor tool set.
Its predecessor is a different matter. Hunters International did ship an encryptor, and when that brand announced its shutdown on 3 July 2025 it said it would give free decryption software to every company it had hit - though that offer required contacting the criminals, could never be independently validated, and the relevant infrastructure has long been unreachable, so it is not a dependable recovery path. If what you are holding is an older case from before mid-2025, with renamed and unreadable files, treat it as Hunters International rather than under the assumptions on this page.
A useful inverse test. If files really are encrypted, extensions really were changed and a ransom note really was dropped, this is probably not World Leaks - it is another family, or someone trading on the name. Re-identify from samples before acting.
Be equally wary of third parties offering to "delete the stolen data" or "take the leak-site entry down". Destruction cannot be verified technically, and in practice such offers are usually ransom payment resold at a markup. We do not pay ransoms and do not negotiate on a client's behalf.
Latest activity
Public monitoring showed the group's .onion leak site at 0% average uptime over the prior 30 days, with the tracker marking the location unavailable/disabled. With no new victims, the operation is assessed as dormant.
SourcesThe last World Leaks victims were posted (St. Francis Xavier Catholic School System, PinnPACK). Public trackers recorded no further postings through 11 September 2026.
SourcesTata Electronics confirmed a cyberattack after World Leaks leaked data reportedly covering Apple-related manufacturing material - component schematics, PCB designs, material specs and SDK files. Tata said operations were unaffected.
Sources
Overview
World Leaks was announced by the Hunters International administrators on 1 January 2025. Six weeks earlier, on 17 November 2024, the same operators had declared the project closed, citing law-enforcement pressure and falling profits - then reversed course and relaunched under a brand built on data theft without encryption. The shift was publicly confirmed by Group-IB and others in April 2025, and on 3 July 2025 the Hunters International brand formally shut down and offered free decryptors to the companies it had hit. Hunters International had been active since late 2023; Group-IB assesses with moderate confidence that it was possibly a rebrand of the dismantled Hive operation, citing heavy code overlap - an assessment, not a confirmed fact.
World Leaks kept the affiliate model. The core team supplies the leak site, the negotiation portal and a purpose-built exfiltration tool; affiliates handle intrusion and collection. Public trackers record somewhere between 174 and 178 named organisations depending on the platform, most of them posted during 2026. Around half the victims are US-based (92 of the 174 listed on one tracker, about 53%), with the remainder spread across roughly 30 countries led by the UK, Brazil, Germany and Canada; sectors cluster in manufacturing, healthcare, professional services and technology. The better-known cases are Dell's Customer Solution Centers in July 2025 (1.3 TB claimed; Dell said the material was primarily synthetic, publicly available or test data), Nike in January 2026 (around 190,000 files and 1.4 TB claimed, with the entry later pulled from the leak site and Nike never confirming the claim) and Tata Electronics in June 2026, where the published directories reportedly covered Apple-related manufacturing documentation and the company confirmed an incident while saying operations were unaffected.
As of 11 September 2026 no new victims have been posted since 21 July 2026 and the leak site has shown zero uptime over a 30-day monitoring window, so this page records the lifecycle as dormant - our own reading of the tracking data, not a shutdown confirmed by any vendor or law-enforcement agency. Public information is limited: there is no encryptor to analyse and the toolchain has never been fully documented. For extortion-only crews, silence usually means infrastructure rebuilding or another rebrand rather than an exit. No public report shows targeted operations against mainland China organisations; exposure for Chinese groups sits mainly with overseas subsidiaries, cross-border branches and upstream suppliers.
How to identify it
The defining trait is the absence of traits. Extensions are unchanged, documents still open, no ransom note is dropped, wallpaper is untouched and production keeps running. Most victims do not discover the intrusion themselves - they are named on the leak site, notified by a third party, or emailed directly by the operators.
On the leak-site side. A .onion address beginning with worldleaks publishes the organisation name, a claimed data volume, a countdown and sample packs, plus the entry point to a per-victim negotiation portal.
On hosts and the network - the more reliable early signals. The appliance item below comes from one public investigation whose timing overlapped with a posting on this leak site; it is not a signature unique to this brand:
- Anomalies on perimeter appliances, especially end-of-life SonicWall SMA 100 series. A non-empty (and immutable-flagged) /etc/ld.so.preload and a file such as libsamba-errors.so.6 posing as a system library are hallmarks of the OVERSTEP userland rootkit documented by Mandiant.
- Administrator or service accounts authenticating to the VPN from unfamiliar addresses outside working hours.
- Bulk sequential reads and archive creation across file servers, ERP and database hosts.
- Large outbound transfers to unfamiliar VPS, cloud storage or anonymous file-sharing endpoints.
Bottom line. If you do see a new extension and a ransom note, World Leaks can essentially be ruled out and the family should be re-identified from samples.
Infection vectors
World Leaks runs on affiliates, so entry tradecraft varies. One chain is documented in far more detail than the rest, but its link to this brand needs stating plainly first:
- End-of-life perimeter appliances. UNC6148, tracked by Google Threat Intelligence (Mandiant), targeted EOL SonicWall SMA 100 series devices, pulling temp.db and persist.db to harvest administrator credentials together with OTP seeds. The OVERSTEP userland rootkit followed, surviving reboots by rewriting /etc/rc.d/rc.fwboot and the boot image, hooking open/readdir/write to hide itself and using sed to strip log evidence. Mandiant could not establish the initial access vector: candidates listed include the CVE-2024-38475 path traversal plus CVE-2021-20038/20035/20039 and CVE-2025-32819, and the report also assesses with moderate confidence that an undisclosed remote code execution flaw may have been used. The campaign ran from October 2024 into mid-2025. On the link itself: an organisation targeted in May 2025 was posted to the World Leaks leak site in June 2025, but Mandiant states it cannot rule out coincidental overlap - so this affiliate should not be treated as the group's only or primary entry route.
- Valid credentials, including OTP. Stolen OTP seeds mean one-time passwords can be replayed, so a password reset alone does not close the door.
- Lateral movement and data discovery. With legitimate credentials inside the network, operators map file servers, ERP and databases, then stage archives.
- Automated exfiltration. The core team supplies affiliates with a purpose-built exfiltration tool, marketed as fully undetectable and supporting - but not requiring - proxy connections, filling the same role as Hunters International's Storage Software.
The point worth stressing: nowhere in this chain is there an encryptor or a detonation moment, so nothing ever forces the business to notice.
Encryption behavior
This family does not encrypt. World Leaks deploys no encryptor. Nothing is renamed, shadow copies are not deleted, database services are not stopped and ESXi datastores are not touched. The damage lands on confidentiality, not availability.
Two consequences follow, and both drive the response:
- Detection is harder. In conventional ransomware, "nothing opens" is a forced alarm. Pure exfiltration provides no such moment, dwell time stretches accordingly, and many organisations learn of the breach on the day they are named.
- "Recovering the data" solves nothing. The data is still local, still intact, and backups are untouched - but a copy sits with the operators. The objective is not restoration; it is to establish what left, cut off access that may still work, and meet notification obligations.
Publicly verifiable detail on the exfiltration tool is thin: built from scratch by the core team, marketed to affiliates as fully undetectable, capable of proxied connections, and designed to automate bulk transfer. No public reverse-engineering report covers its protocol or on-disk artefacts, so do not expect a single IOC to settle attribution - lean on network telemetry and file-access auditing instead.
Its predecessor, Hunters International, was an encrypting family. If your case involves renamed files, work it under that entry.
Assess before you act
Recoverability assessment
There is no "decryption rate" in a pure-exfiltration case. For World Leaks the verifiable work falls into the following layers, highest priority first. We do not pay ransoms and do not negotiate on a client's behalf.
1) Scope and classification of what left - do this first. Reconstruct which directories and which tables were actually read, staged and transferred, using firewall and proxy egress records, file-server auditing, database query and export logs, and appliance logs. Do not take the leak site's claimed volume at face value: in the Dell case 1.3 TB was claimed, and Dell's review found the material was primarily synthetic, publicly available or system test data, with only an outdated contact list genuinely exposed. That gap is not unusual in this group's postings. Then grade the findings across personal data, trade secrets, customer contracts, source code and design files. This inventory is the input to every later decision.
2) Credential and key rotation - the fastest way to stop the bleeding. Treat as compromised: domain and service account passwords, VPN accounts and re-issued OTP bindings (seeds may already be stolen, so a password change alone achieves nothing), device and service certificates with the old private keys revoked, API keys, database accounts and third-party SaaS session tokens.
3) Notification and compliance. Assess reporting thresholds and deadlines under China's Cybersecurity Law, Data Security Law, Personal Information Protection Law and the incident reporting rules; where overseas operations or EU data subjects are involved, GDPR's 72-hour notification and local regulators come into play, and listed companies must evaluate disclosure duties in parallel. Have legal, compliance and security make that call jointly and preserve the reasoning.
4) Second-order risk. Stolen contact lists, contracts and internal process documents are routinely reused for targeted phishing and business email compromise against staff and customers. Watch equally for follow-on fraud from parties posing as "data recovery" or "takedown" services. External messaging should be issued once, after the facts are settled.
5) Monitoring and access reduction. Re-entry through the same door, or resale of the access, is a common sequel. End-of-life perimeter appliances should be replaced rather than patched, and leak-site, dark-web and clearnet monitoring should run for a sustained period.
To be explicit: even after payment, no technique can verify that stolen data was destroyed. What we deliver is a verifiable forensic conclusion and a clearly bounded scope of work.
Our response plan
Hit by World Leaks ransomware? What to do
Containment and evidence preservation
Start at the perimeter: do not reboot, factory-reset or blind-upgrade the appliance. Rootkits such as OVERSTEP live in the boot image and wipe their own log traces, so those actions destroy both the evidence and the basis for judging whether a foothold remains. Image or snapshot the VPN gateway, SMA/SSL VPN appliances, domain controllers, file servers and database hosts; export firewall and proxy egress records plus AD and application audit logs; and preserve the operators' emails and leak-site screenshots.
Actor identification and intrusion reconstruction
Confirm this really is World Leaks rather than someone trading on the name: check the leak-site entry, the sample pack and the proof offered against data that actually exists in your environment. If encrypted files and a ransom note are present, switch to the matching encrypting family instead. Then reconstruct the chain - initial access (EOL appliances, stolen credentials and OTP seeds), persistence, lateral path and the staging points where data was collected.
Exposure assessment
Working from egress telemetry, file-access records and database export logs, define which directories, tables and volumes actually left, and compare that item by item against the claimed figures. Grade the result across personal data, trade secrets, contracts and intellectual property to produce a defensible impact inventory - the document that drives notification wording, external communication and any legal follow-up.
Execution: rotation and access closure
Rotate on a breach-assumed basis: domain and service accounts, VPN accounts with OTP re-enrolment, certificates re-issued and old private keys revoked, API keys, database accounts and SaaS session tokens. End-of-life perimeter appliances should be retired and replaced rather than patched further. In parallel we support regulator notification material, customer and employee messaging, and targeted-phishing warnings.
Attribution, hardening and sign-off
Deliver a full timeline and attribution report naming the initial access point and dwell time. Hardening covers appliance lifecycle management, enforced MFA on VPN with impossible-travel monitoring, egress baselining with large-transfer alerting, file-server and database access auditing, and least-privilege reduction. Sign-off is measured by the original entry path no longer being reproducible, backed by continued monitoring of the leak site and dark web for further postings.
Risk warning
What not to do
- Do not reboot, factory-reset or blind-upgrade the affected VPN/SMA appliance - the rootkit lives in the boot image, so this destroys evidence without reliably removing the foothold
- Do not call it done after resetting administrator passwords: OTP seeds, certificate private keys and session tokens may all be stolen and must be rotated too
- Do not conclude there was no incident because files still open and production is running - pure exfiltration produces no availability signal by design
- Do not quietly pay for a promise to delete the data: it cannot be verified and may cross sanctions and compliance lines
- Do not browse the leak site or download the sample pack from everyday workstations; handle that in an isolated forensic environment
- Do not publish findings or external messaging before the exposure scope is established, or you will be correcting yourself in public
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
ERP System Encrypted by Ransomware
An encrypted ERP is not a single broken database: the application tier, database, attachments and interfaces fail together, halting finance, procurement, production and inventory. This page covers the vulnerability entry points seen in Chinese ERP deployments, the order in which the four tiers are recovered, and how account sets are reconciled at sign-off.
Database Encrypted by Ransomware
When database files are encrypted, every business system that depends on them stops at once. This page explains how we triage an encrypted database, how recoverability is assessed, and when file repair, backup-plus-log restore, or rebuild is the right path.
Related industries
Manufacturing Ransomware Response and Recovery
Ransomware in manufacturing hits information systems and production cadence at the same time: with ERP down there are no orders, with MES down there is no schedule, and an encrypted drawing library takes the process documentation for an entire product line with it. This page covers the asset profile, recovery priorities and targeted defences.
Healthcare Ransomware Response and Recovery
When a hospital is hit, registration, consultation, orders, billing, laboratory and imaging fail at the same moment and care falls back to paper. This page covers the healthcare threat picture, a recovery priority built around clinical continuity, and the handling of patient data and compliance obligations.
Retail and E-commerce Ransomware Response
In retail and e-commerce, ransomware translates directly into an inability to sell: order systems, membership, POS and warehouse fulfilment stop together and losses accrue by the hour. This page covers the sector's attack patterns, a recovery order built around the order-to-fulfilment chain, and handling of member data exposure.
Similar families
- No public decryptor
Hunters International
Hunters International was a RaaS operation built on Hive's source code from October 2023, marked early on by the .locked extension and a Contact Us.txt note. From v6 it encrypted silently without renaming files or dropping notes. The crew shut down in July 2025 and rebranded as the data-theft-only brand World Leaks.
- No public decryptor
Silent Ransom Group
Silent Ransom Group (Luna Moth, Chatty Spider, UNC3753) is a Conti-lineage crew that extorts without encrypting anything. Operators impersonate an internal IT helpdesk by phone, walk staff into a remote-access session, take documents out, then press with a clearnet leak site and calls to employees. The FBI flagged in-person intrusions with USB storage in both May 2025 and May 2026.
- No public decryptor
ShinyHunters
ShinyHunters (ShinyCorp, UNC6240, Bling Libra; MITRE ATT&CK G1057) has run data-theft extortion since 2019 without ever encrypting a file. Operators use voice phishing and stolen SaaS OAuth tokens to pull data out of Salesforce, Snowflake and Databricks, then press with a Tor leak site and a 72-hour bitcoin deadline. Victim postings continued through 2026.
FAQ
World Leaks Frequently asked questions
Does World Leaks encrypt files? Everything still opens - does that mean we are fine?
It does not encrypt. Files opening normally is the expected state with this group and is not evidence that nothing happened. The risk sits entirely with data having been copied out, so the evidence to look at is egress traffic, file-access auditing and appliance logs - not whether documents still open.
Is there a free decryptor for World Leaks?
No, and none is needed - this group does not encrypt. The confusion usually comes from its predecessor: when Hunters International shut down in July 2025 it said it would hand out free decryptors, but that applied to older encrypted cases under that brand, not to World Leaks exfiltration incidents - and since the offer ran through the criminals themselves and could not be independently validated, it is not the same as a usable public decryptor.
They claim more than 1 TB was stolen - how do we verify that?
Verify against your own logs rather than their claim. Useful evidence includes egress session volume and destinations from firewalls and proxies, file-server auditing, database export records, and whether their sample matches real internal data item by item. In the 2025 Dell case 1.3 TB was claimed, and Dell's own review found the material was largely synthetic test data and public datasets.
How is World Leaks related to Hunters International?
They are successive brands run by the same operators. Hunters International announced closure on 17 November 2024, relaunched as World Leaks on 1 January 2025 with encryption dropped in favour of data theft and publication threats, and formally shut the old brand on 3 July 2025 while offering free decryptors. Hunters International itself is assessed by Group-IB, with moderate confidence, as possibly a rebrand of the dismantled Hive operation on the basis of heavy code overlap - an assessment rather than a settled fact.
Is World Leaks still active in September 2026?
It currently looks dormant: public tracking shows no new victims posted since 21 July 2026 and the leak site recorded zero uptime across a 30-day monitoring window. To be clear, that is our reading of the tracking data - no vendor or law-enforcement agency has declared the operation closed. Dormant is not disbanded either -these operators have already announced a shutdown and relaunched under a new name within weeks, so old access paths such as EOL appliances and stolen credentials should still be treated as live.
Will paying make them delete the data?
There is no way to verify it. Destruction cannot be proven technically, so payment buys a promise; a leak-site entry being pulled does not mean the copies are gone. We do not pay ransoms and do not negotiate on a client's behalf. Resources are better spent on scoping the exposure, rotating credentials and meeting notification duties - all of which are verifiable and deliverable.
Sources
- Group-IB: The beginning of the end - the story of Hunters International
- BleepingComputer: Dell confirms breach of test lab platform by World Leaks extortion group
- Google Threat Intelligence: SonicWall SMA exploitation and the OVERSTEP backdoor (UNC6148)
- BleepingComputer: Hunters International ransomware shuts down, releases free decryptors
- BleepingComputer: Hunters International rebrands as World Leaks in shift to data extortion
- ransomware.live: World Leaks group profile and victim listing
- RansomLook: WorldLeaks group profile and leak-site uptime tracking
- BleepingComputer: World Leaks coverage archive
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated