CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement. Known victims: 10
Objectives
Executive Summary
CrazyHunter is a newly emerged ransomware group utilizing Go-based tools and targeting Taiwanese organizations in healthcare, education, and industrial sectors. They employ BYOVD techniques and lateral movement tools like SharpGPOAbuse, aligning with their financial-gain motivation. Their activities are confined to a short operational window in March 2025.
Goals & Targeting
CrazyHunter's strategic objectives are centered on financial gain, achieved through the deployment of ransomware. Their targeting is geographically and sector-specific, focusing on Taiwan due to potential high ransom demands in healthcare and industrial sectors. The group likely selects victims based on their ability to disrupt operations while ensuring payout feasibility.
Enhanced Description
CrazyHunter is a medium-sophistication ransomware group that emerged in early 2025, leveraging the open-source Prince encryptor as a foundation. Specializing in targeting Taiwanese organizations within healthcare, education, and industrial sectors, they have demonstrated a clear focus on financial gain through encryption-based attacks. Their operational methods include the use of Bring-Your-Own-Virus Device (BYOVD) techniques for initial access and lateral movement via SharpGPOAbuse, indicating a preference for sophisticated yet common attack vectors. With 10 known victims to date, CrazyHunter appears to be a focused group targeting sectors with high potential for ransom payouts or sensitive data.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CrazyHunter's campaign activity is brief, primarily observed in March 2025. Their focus on Taiwanese sectors suggests a regional targeting strategy with potential for expansion. The group appears to target organizations with weaker security postures, particularly those lacking robust backup and incident response plans.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their operational tactics and tools, though limited data exists regarding long-term goals or global targeting beyond Taiwan. Further analysis is needed to understand their financial infrastructure and potential expansion.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics