← Back to Ransomware Chk

Crazyhunter

Inactive
CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.
10 Victims
Mar 9, 2025 First Discovered
Mar 30, 2025 Last Discovered
399 Days Inactive
50% Infostealer
0/1 Sites Online
Top Countries
TW 9
US 1
Top Sectors
Technology 3
Healthcare 3
Manufacturing 2
Consumer Services 1
Education 1
Known Locations (1)
7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd.onion
Tools Used
DefenseEvasion
Zemana Anti-Rootkit driver, av-1m.exe (AV bypass), go.exe / go2.exe (BYOVD loader)
Offsec
Donut, Prince Ransomware, SharpGPOAbuse, bb.exe (shellcode loader)
Victims (10)
Zuni Data
TW Technology Discovered: Mar 30, 2025 · Attack est.: Mar 30, 2025
Taiwan - Zuni Data
Analog Integrations Corporation
TW Technology Discovered: Mar 30, 2025 · Attack est.: Mar 30, 2025
Taiwan - Analog Integrations Corporation
Netronix Inc
TW Technology Discovered: Mar 30, 2025 · Attack est.: Mar 30, 2025
Taiwan - Netronix Inc
Johnson Fitness
US Consumer Services Discovered: Mar 24, 2025 · Attack est.: Mar 24, 2025
Johnson Fitness
KD Panels
TW Manufacturing Discovered: Mar 16, 2025 · Attack est.: Mar 16, 2025
Surface Material Supplier — Keding - the interior surface expert, committed to excellence in every detail. Featured Products: ECO+ Laminates, ECO+ Panels, KD Panels & KD Flooring. Guaranteed Quality.
Changhua Christian Hospital
TW Healthcare Discovered: Mar 9, 2025 · Attack est.: Mar 5, 2025
Changhua Christian Hospital
Huacheng Electric
TW Manufacturing Discovered: Mar 9, 2025 · Attack est.: Mar 5, 2025
Due to confidentiality agreement, no details can be disclosed.
Asia University Hospital
TW Healthcare Discovered: Mar 9, 2025 · Attack est.: Mar 5, 2025
Crazyhunter hacked into Asia University-www.asia.edu.tw from 2025.1.27 to 2025.1.29
Asia University
TW Education Discovered: Mar 9, 2025 · Attack est.: Mar 5, 2025
Crazyhunter hacked into Asia University-www.asia.edu.tw from 2025.1.27 to 2025.1.29
Mackay Hospital
TW Healthcare Discovered: Mar 9, 2025 · Attack est.: Feb 5, 2025
Mackay Hospital