PULSE NAME
When Reality Diverges from the Playbook: Darktrace Identifies Encryption in a World Leaks Ransomware Attack
WHITE Unc6148 PetrP.73 2026-03-20 Modified: 2026-04-19
7
IOCs
LOW VOLUME
The article discusses the emergence and operations of the World Leaks ransomware group, a rebranding of the former Hunters International group, which shifted to an Extortion-as-a-Service (EaaS) model, emphasizing data theft and extortion rather than traditional ransomware encryption. This transition signifies a broader trend among cybercriminals where data theft has become more crucial than the encryption used in ransomware attacks, facilitating a stealthier operational approach that targets organizational reputations and pressures victims without the complexities of encryption.
Indicators of Compromise (7)
All CVE FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2021-4034 2026-03-20
CVE CVE-2026-1731 2026-03-20
FileHash-SHA256 5fe6936a69c786c9ded9f31ed1242c601cd64e1d90cecd8a7bb03182c47906c2 2026-03-20
domain backblazeb2.com 2026-03-20
hostname h2.cftunnel.com 2026-03-20
hostname region1.v2.argotunnel.com 2026-03-20
hostname region2.v2.argotunnel.com 2026-03-20