CrazyHunter is a ransomware threat actor and associated malware operation that emerged in 2024 and has been notably focused on organizations in Taiwan, with repeated targeting of the healthcare sector, including hospitals. The group is financially motivated and operates a double-extortion model, combining file encryption with threats to publish stolen data on a leak site if victims do not pay. CrazyHunter is widely assessed as using a ransomware strain derived from or forked from Prince ransomware. The malware is written in Go and targets Windows environments. Reported intrusion patterns indicate the operators commonly exploit weak Active Directory credentials for initial access, then use compromised domain accounts to move laterally and scale impact across enterprise networks. A defining tradecraft element is abuse of Group Policy Objects for propagation, including use of SharpGPOAbuse to push malicious components broadly across domain-joined systems. The operation also demonstrates strong emphasis on defense evasion and rapid enterprise-wide disruption. CrazyHunter has used a bring-your-own-vulnerable-driver technique involving a weaponized Zemana anti-malware driver to elevate privileges and terminate security products. This anti-defense approach is paired with multi-component deployment chains and fallback execution paths to improve resilience during attacks. Its ransomware uses ChaCha20-based partial encryption, typically encrypting data in an intermittent pattern to accelerate execution and reduce the time needed to impact large numbers of files. Per-file key protection has been reported through hybrid cryptographic design using asymmetric protection for session material. The malware also applies exclusion logic to avoid destabilizing the operating system before encryption is complete. Beyond encryption, CrazyHunter maintains a leak site and extortion infrastructure and has used email and Telegram for victim communications. Public messaging associated with the group indicates an attempt to cultivate a recognizable criminal brand. Reporting has also described auxiliary tooling used during extortion and post-compromise operations, including components for monitoring, deletion, or ad hoc file-serving functions. Known aliases include crazy_hunter. CrazyHunter is best characterized as an emerging ransomware group with a Taiwan-centric victimology, aggressive propagation through domain policy abuse, and mature defense-evasion tradecraft centered on BYOVD techniques.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation targeting healthcare organizations (notably hospitals) in Taiwan, using weak Active Directory passwords for initial access, SharpGPOAbuse to weaponize GPOs for rapid domain-wide spread, and BYOVD with a modified Zemana driver (zam64.sys) to terminate security tools; conducts double-extortion via a leak site and demands crypto ransoms.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in March 2024.
Taiwan-focused ransomware operations using open-source tooling for defense evasion and AD abuse, and a customized Prince ransomware variant (.Hunter extension).
New ransomware group actively targeting major industries and companies in Taiwan, contributing to increased ransomware damage there.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.