CrazyHunter is a ransomware threat actor and associated Go-based ransomware family that emerged in 2025 and has shown a strong operational focus on Taiwan, particularly the healthcare sector. Reported victimology includes repeated attacks on Taiwanese hospitals as well as some industrial and technology organizations. The actor is financially motivated and uses data-leak extortion in addition to file encryption. CrazyHunter commonly exploits weaknesses in Active Directory environments for initial access, including weak domain-account passwords, and has also been linked in at least one incident to a suspected removable-media entry vector. After compromise, the actor uses compromised domain credentials and abuses Group Policy Objects for rapid lateral movement and persistence, notably through SharpGPOAbuse. Operations also feature bring-your-own-vulnerable-driver techniques using a weaponized Zemana anti-malware driver to disable or terminate security products, combining privilege escalation with defense evasion. The ransomware itself is widely assessed as a fork or builder-derived variant of Prince ransomware. It is written in Go and uses ChaCha20 for file encryption with ECIES protecting per-file encryption material. Partial encryption is used to accelerate impact. The actor has also used Donut-generated shellcode loaders to execute payloads in memory and auxiliary tooling assessed to support file serving, data exfiltration, and deletion of files that could aid recovery. Public reporting indicates the group operates a leak site and threatens publication of stolen data if ransom demands are not met. Known aliases include crazy_hunter and crazyhunters.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware activity cluster conducting attacks in Taiwan, especially against hospitals and some industrial organizations, using publicly available tooling including a Prince Ransomware-based encrypter, BYOVD to disable security tools, SharpGPOAbuse for lateral movement, and a custom file server/monitoring tool likely for exfiltration and recovery prevention.
Criminal actor described as using stealth tactics with initial access commonly via weak Active Directory credentials/passwords, enabling further compromise of enterprise environments.
Ransomware operation targeting healthcare organizations (notably hospitals) in Taiwan, using weak Active Directory passwords for initial access, SharpGPOAbuse to weaponize GPOs for rapid domain-wide spread, and BYOVD with a modified Zemana driver (zam64.sys) to terminate security tools; conducts double-extortion via a leak site and demands crypto ransoms.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in March 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.