Crazyhunter Ransomware
TrackedThreat actor group tracked in the global ransomware database Β· Last disclosure: Mar 30, 2025
ThreatAI Analysis
Compiled from the ransomware.live profile for Crazyhunter and from this database. Figures and technique mappings are quoted from the source data, not inferred.
Who Crazyhunter is
CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.
Recorded activity
Disclosures attributed to Crazyhunter in this database run from March 2025 to March 2025, totalling 10 victims β 0% of everything tracked here. Crazyhunter has listed victims in 2 countries in this database, most often Taiwan, followed by United States. The sectors appearing most in its listings are Technology, Healthcare, Manufacturing.
Tooling observed in Crazyhunter operations
- Zemana Anti-Rootkit driver
- Donut
- Prince Ransomware
- SharpGPOAbuse
Software reported in use by Crazyhunter. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.
YARA detection rules
crazyhunter.yar
/*
CrazyHunter ransomware
*/
rule CrazyHunter_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.crazyhunter"
description = "Detects CrazyHunter ransomware ransom note"
date = "2026-05-04"
severity = 7
score = 70
strings:
$s1 = "CrazyHunter" ascii nocase
$s2 = "CRAZYHUNTER" ascii
$s3 = "crazy-hunter" ascii nocase
condition:
any of them
}
Community-contributed rules for Crazyhunter, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.
Threat Actor Analysis
Crazyhunter is a ransomware threat group that has disclosed 10 victims in publicly accessible leak site data, representing 0% of all ransomware attacks tracked in this database. The earliest victim disclosure attributed to Crazyhunter in our dataset dates to March 2025.
Geographically, Crazyhunter has targeted organisations in 2 countries. The most frequently targeted nation is Taiwan with 9 victim organisations. Other heavily targeted nations include United States.
Industry-wise, Crazyhunter shows a concentration in the Technology, Healthcare, Manufacturing sectors. These industries are frequently targeted because they manage sensitive data, critical operations, or have lower tolerance for operational downtime β conditions that increase ransom payment likelihood.
Like most modern ransomware operations, Crazyhunter likely employs a double extortion model: encrypting victim files while simultaneously exfiltrating data, creating dual pressure to pay the ransom. Victim organisations that refuse payment face having their data published on the group's dark web leak site.
Note: This profile is generated from public leak site disclosures aggregated via the ransomware.live API. Data is updated automatically. The table below lists the 10 most recent of the 10 disclosures we hold for this group; use the link beneath it to page through all of them.
Recent Victim Disclosures (showing 10 of 10)
| # | Organization | Country | Sector | Date |
|---|---|---|---|---|
| 1 | Analog Integrations Corporation analog.com.tw | πΉπΌ Taiwan | Technology | Mar 30, 2025 |
| 2 | Netronix Inc netronixinc.com | πΉπΌ Taiwan | Technology | Mar 30, 2025 |
| 3 | Zuni Data zunidata.com | πΉπΌ Taiwan | Technology | Mar 30, 2025 |
| 4 | Johnson Fitness johnsonfitness.com | πΊπΈ United States | Consumer Services | Mar 24, 2025 |
| 5 | KD Panels kdpanels.com | πΉπΌ Taiwan | Manufacturing | Mar 16, 2025 |
| 6 | Asia University asia.edu.tw | πΉπΌ Taiwan | Education | Mar 9, 2025 |
| 7 | Asia University Hospital asia.edu.tw | πΉπΌ Taiwan | Healthcare | Mar 9, 2025 |
| 8 | Changhua Christian Hospital cch.org.tw | πΉπΌ Taiwan | Healthcare | Mar 9, 2025 |
| 9 | Huacheng Electric huachengsz.com | πΉπΌ Taiwan | Manufacturing | Mar 9, 2025 |
| 10 | Mackay Hospital mmh.org.tw | πΉπΌ Taiwan | Healthcare | Mar 9, 2025 |
Frequently Asked Questions
What is Crazyhunter ransomware?
Crazyhunter is a ransomware threat group that has claimed 10 victims since its first known activity in March 2025. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.
How many victims has Crazyhunter attacked?
Crazyhunter has claimed 10 victims in our database, representing 0% of all tracked ransomware attacks. The most targeted countries are Taiwan, United States.
Which countries does Crazyhunter target?
Crazyhunter has attacked organizations in 2 countries. The top targeted countries are: Taiwan, United States.
Which industries does Crazyhunter target?
Crazyhunter most frequently targets the Technology, Healthcare, Manufacturing sectors based on victim disclosures in our database.
Is Crazyhunter still active?
Crazyhunter's most recent victim disclosure in our database was on March 30, 2025. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.