TR
Ransomware Victim Public Sector

Treasury of Cote d'Ivoire

Ransomware attack by Hunters ยท Disclosed May 13, 2024 ยท ๐Ÿ‡จ๐Ÿ‡ฎ CI

tresor.gouv.ci/tres/

Date Disclosed
May 13, 2024
2024
Threat Group
Hunters
282 total victims
Industry
Public Sector

ThreatAI Analysis

Compiled from this incident record and the threat intelligence profile for Hunters. Figures and technique mappings are quoted from the source data, not inferred.

About the Hunters group

In mid-October 2023, just a few days before the Europol operation, the source code of the Ransomware Hive was sold, along with its website and older versions developed in Golang and C (although this purchase has only been reported by the actors without concrete evidence). The buyer of this new source code was the group Hunters International, who claimed to have fixed the bugs in the Ransomware Hive that were responsible for preventing file decryption in some cases. The group also stated that file encryption would not be their primary focus; instead, they would use data theft as a method to pressure victims during extortion attempts. Hunters has listed 307 victims since September 2021.

How Hunters is documented to operate

Native API T1106 Execution

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference โ†’
Shared Modules T1129 Execution

Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom functions or invoking OS API functions (i.e., Native API). Adversaries may use this functionality as a way to execute arbitrary payloads on a victim system. For example, adversaries can modularize functionality of their malware into shared objects that perform various functions such as managing C2 network communications or execution of specific actions on objective. The Linux & macOS module loader can load and execute shared objects from arbitrary local paths.

Mitigations: Execution Prevention

MITRE ATT&CK reference โ†’
Boot or Logon Autostart Execution T1547 Persistence Privilege Escalation

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

MITRE ATT&CK reference โ†’
Obfuscated Files or Information T1027 Stealth

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.

Mitigations: User Training, Behavior Prevention on Endpoint, Antivirus/Antimalware, Audit

MITRE ATT&CK reference โ†’
Process Discovery T1057 Discovery

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. In Windows environments, adversaries could obtain details on running processes using the Tasklist utility via cmd or <codeGet-Process</code via PowerShell.

MITRE ATT&CK reference โ†’

MITRE ATT&CK techniques attributed to Hunters across its recorded activity, not a finding about how Treasury of Cote d'Ivoire was reached.

Incident Analysis

Treasury of Cote d'Ivoire was targeted by Hunters ransomware, one of the most active ransomware groups in our database with 282 confirmed victims globally. The attack was disclosed on May 13, 2024, when Treasury of Cote d'Ivoire appeared on the group's dark web leak site.

Treasury of Cote d'Ivoire is based in CI , operating in the Public Sector sector. CI ranks #102 globally for ransomware attacks, with 6 victims in our database.

Sector context: Organisations in this sector hold valuable data and operational systems that ransomware groups seek to exploit for financial gain through encryption and data exfiltration.

Hunters typically employs a double extortion model: first exfiltrating sensitive data from the victim's systems, then deploying ransomware to encrypt files. Victims face two simultaneous threats โ€” paying to restore access and paying to prevent publication of stolen data. The group's leak site publishes victim names and exfiltrated data as leverage.

Data source: This incident record is sourced from public ransomware group leak site disclosures aggregated via the ransomware.live API. Disclosure date reflects when the victim was published on the leak site, which may differ from the initial date of compromise. This platform does not publish or link to stolen data. Last data update: Sep 6, 2026 04:00 UTC.

Frequently Asked Questions

Was Treasury of Cote d'Ivoire attacked by ransomware?

Yes. Treasury of Cote d'Ivoire was listed as a victim of the Hunters ransomware group on May 13, 2024. The organisation is based in CI and operates in the Public Sector sector. The disclosure appeared on the group's dark web leak site.

Which ransomware group attacked Treasury of Cote d'Ivoire?

Treasury of Cote d'Ivoire was attacked by Hunters ransomware. Hunters is one of the most active ransomware groups, having claimed 282 victims globally. The group typically employs a double-extortion model: encrypting the victim's files and threatening to publish stolen data.

When did the Treasury of Cote d'Ivoire ransomware attack occur?

The ransomware attack on Treasury of Cote d'Ivoire was disclosed on May 13, 2024. This date reflects when the victim was published on the threat group's leak site, which may differ from the actual date of initial compromise.

What data was stolen in the Treasury of Cote d'Ivoire ransomware attack?

The specific data stolen from Treasury of Cote d'Ivoire has not been independently verified by this platform. Ransomware groups typically exfiltrate data before encrypting systems and use the threat of publication to pressure victims. As a Public Sector organisation, Treasury of Cote d'Ivoire likely held sensitive business data, client information, and operational records.

How can organisations protect against Hunters attacks?

To defend against Hunters and similar threat actors, organisations should: maintain regular offline backups tested for restoration; implement network segmentation to limit lateral movement; deploy multi-factor authentication on all remote access; use endpoint detection and response (EDR) tools; conduct regular phishing and security awareness training; and monitor threat intelligence feeds for indicators of compromise (IOCs) associated with active groups.