Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 1 actor

CrazyHunter

CrazyHunter is a Go-based ransomware family targeting Windows systems. Multiple sources in the provided content describe it as a fork of Prince ransomware, first observed in mid-2024, and tracked by Trellix as a rapidly evolving threat. It has primarily targeted organizations in Taiwan, with at least six known victims, most notably hospitals and other healthcare entities.

Reported initial access commonly involves exploiting weaknesses in Active Directory environments, including weak domain account passwords. For propagation, operators abuse Group Policy Objects using SharpGPOAbuse to spread rapidly across enterprise networks. The malware also uses a bring-your-own-vulnerable-driver technique for privilege escalation and defense evasion, deploying a modified Zemana anti-malware driver, zam64.sys (reported as version 2.18.371.0), to terminate security processes.

The deployment chain described in the content includes ru.bat orchestrating components such as go.exe and go2.exe as AV-killer tools, go3.exe as the primary encryptor, bb.exe as a Donut loader for in-memory execution of crazyhunter.sys shellcode, and crazyhunter.exe as a backup encryptor. A fallback anti-malware interference component, av-1m.exe, may also be used. The ransomware enumerates drives, applies exclusion lists for specific extensions, filenames, and directories, and encrypts files using ChaCha20 with a partial-encryption scheme that encrypts one byte and skips the next two. Per-file keys and nonces are protected with ECIES. Encrypted files are typically renamed with a .hunter or .Hunter extension.

CrazyHunter maintains a data leak site and uses double-extortion pressure by threatening to publish stolen victim data. The content states the leak site includes a “Strategic Manifesto” and references “Premium Criminal Branding Services.” Victim communications are conducted via email and Telegram, with cryptocurrency demanded for payment. Reported contact and infrastructure indicators include attack-tw1337@proton.me, Telegram @Magic13377, and the Tor onion address 7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd.onion. Additional reported operational tooling includes file.exe, described as either a local file server on port 9999 or a monitoring/deletion tool used during extortion, and a wallpaper-change routine that downloads an image from ncmep.org.

High-confidence indicators and artifacts mentioned in the content include zam64.sys, ru.bat, go.exe, go2.exe, go3.exe, bb.exe, crazyhunter.sys, crazyhunter.exe, av-1m.exe, gpo.exe, file.exe, the .hunter/.Hunter file extension, the Proton email address, the Telegram handle, the onion site, and the wallpaper URL hosted on ncmep.org. One source in the content also notes Taiwanese authorities linked the attacks to a Chinese security firm, but attribution details are limited in the provided material.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
CrazyHunter

CrazyHunter, a Go-developed ransomware, employs advanced encryption and delivery methods targeted against Windows-based machines. It uses a data leak site to publicize victim information.

via trellix blogtrellix.com
ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
Jan 15, 2026
ThreatsDay Bulletin: AI Voice Cloning Exploit, Wi-Fi Kill Switch, PLC Vulns, and 14 More Stories

Go-based ransomware (fork of Prince) targeting Windows systems; uses AD weaknesses/weak domain passwords for initial access, SharpGPOAbuse for GPO-based distribution and propagation, and a modified Zemana anti-malware driver for BYOVD privilege escalation and security process termination; operates a data leak site.

Read more
data breaches netNews
Jan 12, 2026
CrazyHunter ransomware escalates with advanced intrusion tactics, six Taiwan healthcare victims confirmed

Go-based ransomware targeting Windows systems; uses advanced encryption and delivery methods, incorporates enhanced network intrusion techniques and anti-malware evasion, and operates a data leak site for extortion.

Read more
risky biz rssNews
Jan 11, 2026
Risky Bulletin: Apex Legends streamers hacked again

Ransomware strain used in attacks against Taiwanese organizations, later linked to a Chinese security firm.

Read more
security online infoNews
Jan 8, 2026
CrazyHunter: The "Ruthless" Ransomware Stalking Healthcare

Ransomware strain (first seen mid-2024) that targets organizations (notably healthcare in Taiwan), spreads via AD/GPO abuse (SharpGPOAbuse), uses BYOVD with a modified Zemana driver (zam64.sys) to terminate security tools, and encrypts files quickly using ChaCha20 with partial encryption (1 byte encrypted, 2 bytes skipped) to increase speed and potentially evade I/O-based detection; supports extortion via data leak threats and tooling (e.g., file.exe) for monitoring/deletion during extortion.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.