Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

World Leaks – Bulk Data Staging Consistent with Inherited Hunters International Tooling

Worldleaks Exfiltration Sentinel
MITRE ATT&CK
Transfer Data to Cloud Account
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group profile (worldleaks); public reporting on the Hunters International → World Leaks rebrand
What This Detects
World Leaks is a January 2025 rebrand of Hunters International that dropped the encryption payload but, per public reporting, inherited much of its predecessor's infrastructure and exfiltration tooling (RClone/WinSCP bulk transfer).
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName in~ ("rclone.exe","winscp.exe","winscp.com")
| where ProcessCommandLine has_any ("copy","sync","/command","sftp://")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, AccountName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.