Crazyhunter

Inactive
CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.
10 Victims
Mar 5, 2025 First Discovered
Mar 30, 2025 Last Discovered
535 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd.onion
Tools Used
DefenseEvasion
Zemana Anti-Rootkit driver, av-1m.exe (AV bypass), go.exe / go2.exe (BYOVD loader)
Offsec
Donut, Prince Ransomware, SharpGPOAbuse, bb.exe (shellcode loader)
Victims (10)

Detailed victim list temporarily unavailable

This group has 10 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.