BlackHunt is a ransomware group that first emerged in late 2022, notably in November, initially operating as a C++-based ransomware variant. The group, or the threat actor identified as "blackhunt," evolved to offer Ransomware-as-a-Service (RaaS) projects by early 2024, including the Black Hunt 2.0 and Wing ransomware strains, both developed using leaked LockBit ransomware builder code. Their primary motivation is financial gain through double extortion, encrypting victim files and threatening to leak stolen data. This group is distinguished by its use of repurposed LockBit code and its transition to a RaaS model, explicitly advertising its services on underground forums like RAMP with a focus on compromising large targets.