SharpRhino Strikes: Hunters International Targets Network Admins with Angry IP Scanner Malware

Hunters International’s latest malware, SharpRhino, targets network admins via a fake Angry IP Scanner. Hidden in typo-squatted sites, it embeds itself to spread across networks, using Rust-based encryption to lock files. Quorum Cyber links the gang to Hive ransomware, suggesting a rebrand.

Pro Dashboard

Hot Take:

Move over, Hive, there’s a new villain in town! Hunters International is out here turning networking tools into cyber booby traps. It’s like finding out your friendly neighborhood handyman is secretly a supervillain. Who knew network admin tools could be so… sharp?

Key Points:

  • Hunters International is targeting network admins with malware disguised as Angry IP Scanner.
  • The malware, named SharpRhino, is hidden on typo-squatted websites.
  • SharpRhino uses a Rust-based encryptor and establishes persistence through registry alterations.
  • The gang employs double extortion tactics, copying data before encrypting it and demanding ransom.
  • Hunters International is suspected to be a rebrand of the notorious Hive ransomware gang.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?