Introduction
Hunters International ransomware gang announced last month that it was shutting down, but many ransomware observers questioned this announcement, suggesting instead that the gang was rebranding or merging some Hunters International operators with other ransomware gangs. Hunters International appears to be responsible for more than 200 attacks on organizations, including American government agencies and healthcare corporations.
Ransomware observers have noted that Hunters International has made similar announcements before. Those premature announcements appeared to be related to slumping profits and law enforcement pressure. Hunters International also appeared to modify its practices just a few months ago, maybe rebranding or masquerading as a gang known as “World Leaks” that focused on data theft and extortion only. The site apparently looked similar to the Hunters International site. Another ransomware observer had reported that some Hunters International operators had left to start World Leaks because of a disagreement over the use of encryption, but Hunters International operators remained. These movements among ransomware gangs are common, as Hunters International operators apparently included former Hive ransomware operators.

Hunters International posted this announcement on the gang’s dark web leak and extortion site. This announcement could be described as oddly benevolent for some, such as the other ransomware partners the gang said it recognized will be impacted by Hunters shutting down. Hunters International also said it would provide decryption software “to all companies that have been affected by our ransomware”. This is classic ransomware doublespeak that reminds me of much of the phrasing and language in an Indonesian dialect known as Javanese, where culturally nothing is direct. For example, when I ran into a tree with my car, it was the tree that hit me, not me that drove into the tree. When you spilled coffee onto my shirt, it was not you that spilled coffee, but the coffee fell on me. When Hunters International talks about victimizing people, they appear to write platitudes understanding the “challenges that ransomware attacks pose”. This kind of commentary is worth reporting on because Hunters International decision makers are engaged in some kind of performance, but this announcement does not tell us much.
What do we really know about why a ransomware gang might decide to rebrand or shut down? The above analysis is helpful, highlighting some of the suggested explanations for why some operators may decide to join other gangs or why law enforcement pressure may have influenced Hunters International to try to rebrand or to try to appear to be limiting ransomware operations. But at most we can only speculate.
This article offers an analytical framework for group dynamics that researchers can apply today. This article recognizes there are significant gaps in information on these ransomware gangs and that finding out what’s really going on inside a gang is quite difficult.
This article also introduces some frameworks of criminology research that have been applied to armed robbery crews and diverse communities of criminals and fraudsters. What researchers often find is that criminal gangs are not homogenous, even if in a ransomware context most of the attackers appear to be from Russian-speaking territories or based in Russia.
This framework for group dynamics and these criminology models are a starting point. Ransomware gangs include friends and lovers and pressure to perform for foreign governments. Rarely do we know about those relationships, but we can apply these frameworks to recharacterize the possible motivations behind some of the decisions we think we see out here.
Groups of relationships in ransomware gangs: another framework for understanding gang decision making and gang turnover
Group dynamics researcher Don Forysth defined a group as two or more people in relationship. Those relationships can span dozens of people or just be between two people. The emphasis has always been on social relationships because people are generally interdependent and influence each other. A ransomware gang of five operators could have multiple different social groups.
There are emotions and affect people in these groups experience as well that have been called identity-based emotions, because of what people in a ransomware gang for example might experience together while attacking a target like an American federal law enforcement agency. The size of a relational group influences the nature of that group in many ways, because of the unique characteristics of each member of that group who has some kind of relationship with others. But whether there is an organizational boundary to this group or not is less important than what kind of a relational boundary or boundaries there are between members of that group.
Forsyth characterized some of these structures for groups in general as norms and roles. Norms are consensual and typically vocalized or demonstrated expectations and behaviors among group members at the group level, so if someone leaves the group or joins the group those norms are usually constant. Roles likewise describe some of those same expectations at a group level, but usually for categorized or named positions such as director or teacher, for example. Forsyth once described to me the role of professor in a university and the norms among his department peers with whom he has different relationships or groups, and then the roles of husband and father when he was at home and trying to grade university papers. He noted that group norms and roles are not always clear, and, in some cases, people may not realize there was some expectation until a norm is violated. This modeling can be unique to each group, but the behaviors they demonstrate provide insight into how to build trust in those groups and how to break trust in those groups.
Forsyth wrote that we probably learn the most about a group when studying the structure. Forsyth cautioned that we could misperceive the “’groupiness’” of a group we think we see based how they dress or how they talk if we saw them walking down the street together. Forsyth used an example of a vehicle. Someone may see four wheels and a trunk and a hood and a windshield and correctly see a vehicle rather than these individual parts of the car, but relational groups are much more complicated and changing.
This framework for group dynamics is useful even when there are major gaps in information. When I was an FBI profiler, I would present this framework for FBI agents, so they understood better what to look for and how to understand what they saw.
Criminology models that might suggest how diverse ransomware gangs probably are
Criminologist James Haran wrote a seminal work on the sociological profile of 500 armed bank robbers in the 1980s, based on nearly a decade of demographic data on these armed robbers. Haran wrote at the time that robbery was “considered the most personally threatening offense to the man in the street”. We could say ransomware is just as fearsome to most organizations today.
Haran developed several typologies or categories of armed bank robbers based on their motivations for their crime, suggesting applying this framework of categorization could enable the justice system to reduce sentences for more “amateur types” for example who were robbing banks so they could buy heroin for their self. The “amateur types” often reflected much different backgrounds in experiences and skills related to this crime and their intention to commit robbery, compared to more experienced and organized robbers.
Criminologist George-Mircea Botescu more recently distinguished the plurality in organized crime by emphasizing the criminal intent and roles that differed among “perpetrators, accomplices, and instigators”. While he recognized how participation in committing crimes can normalize how these different people work together, there is a need to make a distinction between the kinds of groups of people in relationships who are communicating directly with each other and are emotionally attached to each other, and other groups where the relationships in those groups are organizationally mediated by others. This exclusion is much more common online among anonymized attackers or people with marginal roles in ransomware affiliates. Many ransomware affiliates pay a cut to a developer they have never met.
These differing roles remind me of a ransomware event involving a government agency where I assisted that agency in a consulting role as an FBI profiler at the time. The agency representatives prepared their response to the ransomware customer service representative as if he was a ransomware decision maker. They couldn’t get past how polite he was and how good his English was. But he had a role as an accomplice at most.
The response to this ransomware gang did not include information on the group dynamics of this gang or who was closer to who among the gang’s decision makers, but I was able to provide recommendations for communication with this customer service representative that responded to what we did know about the norms and roles of this kind of communication and what might be the expectations among some of the suspected gang decision makers when targeting government. This framework for group dynamics and these models of criminology also reminds us to reconsider each ransomware personality as an individual who has his or her own relationships.
Criminologists Thomas Grund and James Densley examined black street gangs in London about a decade ago, finding there was much greater ethnic heterogeneity or complexity than imagined. Grund and Densley wrote that in the United States many gangs appear “ethnically homogeneous and thus reflect the segregated ghettos and barrios from which they originate”, and that these gangs are often labeled according to a singular ethnic or racial category, like Asian or Hispanic. Grund and Densley highlighted that research has continued to conclude that there are few gangs that share a single ethnic identity. Grund and Densley wrote that there has been a “racialized construction of the gang” by law enforcement and the news media.
Grund and Densley found in their study of black street gangs in London that there was considerable conflict between Jamaican ‘black’ street gangs and Somali and British ‘black’ youth who were mostly from Muslim communities.
In a closer examination of one ‘black’ street gang in London, Grund and Densley also found that there did not appear to be any specialization of certain types of crime related to someone’s race. Understanding the ethnic differences among people in the same gang was crucial to differentiating the “inner workings” of the gang. There was a “co-offending” pattern Grund and Densley observed among gang members who did share a similar ethnic background, however. This is a rare study on gang relationships and practices.
The diversity of ransomware gangs includes not just different ethnic or cultural backgrounds, but different “naturalistic” life events and experiences
Former REvil affiliate ransomware operator Yaroslav Vasinskyi recently shared some candid explanations for why he tried to get out of REvil ransomware attacks, such as death threats to himself and his family, suggestions someone would try to remove and sell his organs and his girlfriend’s organs, the death of close family members, the threat of sexual assault in prison, REvil’s alleged ransomware attack on a hospital that may have resulted in the death of a child. These are a few explanations, but none of them are related to ransomware gang rebranding or trying to keep law enforcement and researchers confused and aloof.
These are real life examples that reflect much of the naturalistic decision making that is largely absent from analysis of ransomware gang activity and the industry’s generally speculative behaviors of ransomware gang operators. This kind of dynamic approach to understanding how people make decisions explains that there is much we do not know about what or who might be influencing someone’s decisions, including everything from close relationships to “feedback loops” to restrictions at a job to the attitudes someone’s friends and family may have about something the decision maker is involved in. But even when there are these kinds of gaps in information, this is the kind of information we look for to explain or anticipate their decisions.
Because Vasinskyi felt at that time that he had no way out of the ransomware gang and he believed that he was being threatened, he agreed to do one final job for REvil.
The resulting Kaseya supply chain attack was suspected to be associated with Russian government interests as well, but much of the analysis did not focus on people like Vasinskyi at the time or other REvil operators and decision makers that had been with the gang much longer. This attack became one of the largest and most damaging ransomware events in attack history.
Vasinskyi also explained that several months after the Kaseya attack, when some of REvil’s decision makers had disappeared, another operator was unsure about restoring operations, but because he had access to the infrastructure and backups, he then became the new REvil leader. “That is the only reason [this operator] became the new leader”, Vasinskyi wrote.
Much of the decision making and behaviors I have observed analyzing these kinds of gangs when I was with the FBI and more recently as a researcher interviewing cybercrime felons, has largely reflected their relationships with other people that demonstrate those relational “groups”. The motivations that really influence these ransomware gang personalities involve other people they care about and what they are experiencing in their life at the time, not organizational goals.
About Analyst1
Threat intelligence teams often struggle to bridge the gap from insight to action. Analyst1 is the Orchestrated Threat Intelligence Platform designed to resolve this issue. It automatically organizes threat data, links it to your assets and vulnerabilities, and customizes views for different roles. Analyst1’s orchestration layer streamlines workflows and automates reliable actions by integrating with SIEM, ticketing, and vulnerability management systems. From Fortune 500 financial institutions to national security agencies, enterprises trust Analyst1 to unify their defenses, significantly reducing their response time from days to minutes.