CrazyHunter is an emerging ransomware threat actor and malware family primarily associated with attacks in Taiwan, with a pronounced focus on healthcare organizations and additional victimization in industrial and technology-related enterprises. Activity is reported from early 2025, although some reporting places its emergence in 2024. The group is best known for repeated attacks on Taiwanese hospitals and for combining commodity and open-source offensive tooling with effective enterprise-wide propagation and defense evasion. CrazyHunter is widely assessed as a ransomware operation built from or forked from the Prince ransomware codebase. Its Windows payloads are written in Go and use ChaCha20 for file encryption with ECIES protecting per-file encryption material. Reported samples implement partial encryption to accelerate impact. The operators have also maintained a leak site and threatened publication of stolen data, indicating extortion in addition to encryption. Operationally, CrazyHunter has been linked to initial access through weak Active Directory credentials, and in at least one incident a USB device was reportedly involved. After compromise, the actor abuses Group Policy Objects using SharpGPOAbuse to achieve lateral movement and persistence across domain-joined systems. For privilege escalation and defense evasion, CrazyHunter uses a bring-your-own-vulnerable-driver technique involving a weaponized Zemana driver to terminate security products, including endpoint protection tools. Reporting also links the actor to in-memory execution via Donut-generated shellcode and to use of an auxiliary utility assessed to support file serving, monitoring, deletion of recovery-related files, and likely data exfiltration. The actor appears to rely heavily on publicly available or leaked tooling rather than bespoke tradecraft, but has still demonstrated the ability to cause severe operational disruption. Known aliases include crazy_hunter. CrazyHunter has also been referenced in ransomware tracking alongside other Prince-derived variants such as Black (Prince), Wenda, and UwU, though those are separate variants rather than confirmed sub-groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware activity cluster conducting attacks in Taiwan, especially against hospitals and some industrial organizations, using publicly available tooling including a Prince Ransomware-based encrypter, BYOVD to disable security tools, SharpGPOAbuse for lateral movement, and a custom file server/monitoring tool likely for exfiltration and recovery prevention.
Ransomware operation targeting healthcare organizations (notably hospitals) in Taiwan, using weak Active Directory passwords for initial access, SharpGPOAbuse to weaponize GPOs for rapid domain-wide spread, and BYOVD with a modified Zemana driver (zam64.sys) to terminate security tools; conducts double-extortion via a leak site and demands crypto ransoms.
Named as a new ransomware variant/gang emerging in 2024 and associated with victim claims posted in March 2024.
Taiwan-focused ransomware operations using open-source tooling for defense evasion and AD abuse, and a customized Prince ransomware variant (.Hunter extension).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.