CrazyHunter is a Go-based ransomware family assessed as a fork or builder-derived variant of Prince ransomware. It emerged by early 2025 and has been used primarily against organizations in Taiwan, with repeated targeting of the healthcare sector, including hospitals, and some activity against industrial organizations. The operation uses a data leak site to pressure victims, indicating double-extortion-style tactics in which stolen data may be exposed in addition to file encryption.
On Windows systems, CrazyHunter combines enterprise intrusion tradecraft with ransomware deployment. Reported initial access has included exploitation of weak Active Directory credentials, and at least one incident was reportedly linked to a USB device. After compromise, operators have used SharpGPOAbuse to weaponize Group Policy Objects for lateral movement and persistence across domain-joined environments.
A notable feature of CrazyHunter operations is the use of bring-your-own-vulnerable-driver techniques to disable security controls. The operators deploy a vulnerable Zemana anti-malware driver to elevate privileges and terminate defensive processes, including Microsoft Defender and Trend Micro components. The intrusion set has also used Donut-generated shellcode and in-memory loading to reduce detection, along with auxiliary tooling assessed to support file serving, monitoring, deletion, and exfiltration during extortion operations.
The ransomware encryptor is written in Go and uses ChaCha20 for file encryption with ECIES protecting per-file keys and nonces. Multiple reports describe partial encryption behavior inherited from the Prince codebase, enabling faster impact by encrypting portions of files rather than full contents. The malware enumerates drives, traverses directories, applies exclusion lists to avoid destabilizing the host, and drops a ransom note. Operationally, CrazyHunter appears to rely heavily on reused or publicly available tooling, but its combination of credential abuse, GPO-based propagation, BYOVD defense evasion, and rapid encryption makes it a significant threat to Windows enterprise environments, especially healthcare networks where downtime and data exposure create acute pressure to pay.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CrazyHunter, a Go-developed ransomware, employs advanced encryption and delivery methods targeted against Windows-based machines. It uses a data leak site to publicize victim information.
1 distinct technique documented for this family, organized by ATT&CK tactic.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware encrypter used in the incident that encrypts files using ChaCha20 and ECIES, drops a ransom note, loops through drives and directories while skipping blocklisted items, and was also converted to shellcode for in-memory loading via bb.exe to evade detection.
Go-based ransomware (fork of Prince) targeting Windows systems; uses AD weaknesses/weak domain passwords for initial access, SharpGPOAbuse for GPO-based distribution and propagation, and a modified Zemana anti-malware driver for BYOVD privilege escalation and security process termination; operates a data leak site.
Go-based ransomware targeting Windows systems; uses advanced encryption and delivery methods, incorporates enhanced network intrusion techniques and anti-malware evasion, and operates a data leak site for extortion.
Ransomware strain used in attacks against Taiwanese organizations, later linked to a Chinese security firm.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.