logo

SharpRhino malware targets IT admins – Hunters International gang suspected

ID: 9ec6e116-ace4-5602-a668-e4916cc2f5a2

STIX ID: report--9ec6e116-ace4-5602-a668-e4916cc2f5a2

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-08-07

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Quorum Cyber discovered SharpRhino, a C# malware trojan distributed via typo-squatted Angry IP Scanner installers attributed to Hunters International; the malware achieves persistence via registry changes, communicates with multiple C2 servers, exfiltrates data and encrypts files with a Rust-based encryptor as part of a double-extortion ransomware campaign, and Hunters International has claimed many global attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.