CrazyHunter is a Go-based ransomware family, assessed by Trellix as a fork of Prince ransomware first observed in mid-2024, that targets Windows systems. Reporting indicates it has primarily targeted organizations in Taiwan, with at least six known victims, many of them hospitals and healthcare organizations. It uses a data leak site to publicize victim information and threaten publication of stolen data if ransom demands, made in cryptocurrency, are not paid.
Initial access is reported to commonly involve exploitation of weak Active Directory passwords and other AD weaknesses. For propagation, operators abuse Group Policy Objects using SharpGPOAbuse to spread rapidly across enterprise networks. For defense evasion and privilege escalation, CrazyHunter uses a bring-your-own-vulnerable-driver technique with a modified Zemana anti-malware driver, zam64.sys, to terminate legitimate security processes.
The malware uses ChaCha20 for file encryption and ECIES to protect per-file keys and nonces. It implements partial encryption using a 1:2 pattern, encrypting one byte and skipping the next two, to accelerate impact and potentially reduce detection based on sustained disk I/O. Encrypted files are typically appended with the .hunter extension. Reported operational components include ru.bat for orchestration, go.exe and go2.exe as AV-killer components, go3.exe as the primary encryptor, bb.exe as a Donut loader, crazyhunter.sys shellcode, crazyhunter.exe as a backup encryptor, and file.exe, which has been described as supporting extortion operations by acting as a file server or monitoring/deletion tool.
Known communications and infrastructure mentioned in reporting include attack-tw1337@proton.me, Telegram @Magic13377, and the Tor onion address 7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd.onion. A wallpaper-change routine was also reported to download an image from ncmep.org. Some reporting notes Taiwanese authorities later linked the attacks to a Chinese security firm or described the actors as a Chinese hacker group, but attribution details are limited in the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CrazyHunter, a Go-developed ransomware, employs advanced encryption and delivery methods targeted against Windows-based machines. It uses a data leak site to publicize victim information.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based ransomware (fork of Prince) targeting Windows systems; uses AD weaknesses/weak domain passwords for initial access, SharpGPOAbuse for GPO-based distribution and propagation, and a modified Zemana anti-malware driver for BYOVD privilege escalation and security process termination; operates a data leak site.
Go-based ransomware targeting Windows systems; uses advanced encryption and delivery methods, incorporates enhanced network intrusion techniques and anti-malware evasion, and operates a data leak site for extortion.
Ransomware strain used in attacks against Taiwanese organizations, later linked to a Chinese security firm.
Ransomware strain (first seen mid-2024) that targets organizations (notably healthcare in Taiwan), spreads via AD/GPO abuse (SharpGPOAbuse), uses BYOVD with a modified Zemana driver (zam64.sys) to terminate security tools, and encrypts files quickly using ChaCha20 with partial encryption (1 byte encrypted, 2 bytes skipped) to increase speed and potentially evade I/O-based detection; supports extortion via data leak threats and tooling (e.g., file.exe) for monitoring/deletion during extortion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.