Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors crazyhunter

Description

CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement. Known victims: 10

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

CrazyHunter is a newly emerged ransomware group utilizing Go-based tools and targeting Taiwanese organizations in healthcare, education, and industrial sectors. They employ BYOVD techniques and lateral movement tools like SharpGPOAbuse, aligning with their financial-gain motivation. Their activities are confined to a short operational window in March 2025.

Goals & Targeting

CrazyHunter's strategic objectives are centered on financial gain, achieved through the deployment of ransomware. Their targeting is geographically and sector-specific, focusing on Taiwan due to potential high ransom demands in healthcare and industrial sectors. The group likely selects victims based on their ability to disrupt operations while ensuring payout feasibility.

Enhanced Description

CrazyHunter is a medium-sophistication ransomware group that emerged in early 2025, leveraging the open-source Prince encryptor as a foundation. Specializing in targeting Taiwanese organizations within healthcare, education, and industrial sectors, they have demonstrated a clear focus on financial gain through encryption-based attacks. Their operational methods include the use of Bring-Your-Own-Virus Device (BYOVD) techniques for initial access and lateral movement via SharpGPOAbuse, indicating a preference for sophisticated yet common attack vectors. With 10 known victims to date, CrazyHunter appears to be a focused group targeting sectors with high potential for ransom payouts or sensitive data.

Key Capabilities

  • Go-based ransomware
  • BYOVD techniques
  • SharpGPOAbuse for lateral movement
  • Leveraging open-source tools

MITRE ATT&CK Tactics

Credential Access
Lateral Movement
Persistent Access
Data Exfiltration

ATT&CK Techniques

T1270.003
T1566.001
T1093.004
T1078.002

Software / Tooling

Go ransomware
SharpGPOAbuse

Campaigns & Victims

CrazyHunter's campaign activity is brief, primarily observed in March 2025. Their focus on Taiwanese sectors suggests a regional targeting strategy with potential for expansion. The group appears to target organizations with weaker security postures, particularly those lacking robust backup and incident response plans.

IOC Patterns

  • Use of BYOVD techniques
  • Leverage GPOs for lateral movement
  • Encrypted communications via custom tools

Recommended Actions

  • Harden GPO configurations
  • Monitor for suspicious GPO changes using System Monitored Attack (Sysmon)
  • Segment networks to limit lateral movement potential
  • Educate employees on phishing and BYOVD risks
  • Implement robust backup solutions and regular testing

Suggested Tags

APT
ransomware
healthcare
education
industrial

Confidence Assessment

High confidence in their operational tactics and tools, though limited data exists regarding long-term goals or global targeting beyond Taiwan. Further analysis is needed to understand their financial infrastructure and potential expansion.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
APT
ransomware
healthcare
education
industrial

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 5, 2025
Last Seen
Mar 30, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.