Uptime Hamster: 10d 12h 29mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza crazyhunter

crazyhunter

2 incidentes 2 paises 1 sectores ransomware TW Ultimo: 2026-06-29
Ver en IntelTracker → APTTrail →
CrazyHunter is a financially motivated ransomware group that emerged in early 2025, known for its aggressive and highly targeted attacks primarily against organizations in Taiwan. The group distinguishes itself through its heavy reliance on open-source tools, notably the "Prince Ransomware" builder, and its use of Bring-Your-Own-Vulnerable-Driver (BYOVD) techniques for defense evasion. While there was initial internal monitoring of their activities since January 2025, their debut was marked by a significant attack on a Taiwanese medical institution in February 2025, quickly followed by the establishment of a data leak site listing exclusively Taiwanese victims. The group's operational model emphasizes rapid compromise, data encryption, and exfiltration, utilizing a structured criminal branding system on their leak site that includes options for delaying data publication for a fee and offering vulnerability remediation guides.

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-011-CrazyHunter-March-2025
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-011-CrazyHunter-March-2025
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-011-CrazyHunter-March-2025
Repositorioupgithub.comBushidoUK ToolMatrix CommunityReports: CR-011-CrazyHunter-March-2025
DLS / leak siteuplabs.withsecure.comBushidoUK ToolMatrix CommunityReports: CR-011-CrazyHunter-March-2025
DLS / onionunknown7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd.onioncrazyhunter
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: crazyhunter
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) Taiwan (1)

Paises objetivo (SOCRadar)

ChinaTaiwan, Province of ChinaUnited States

Sectores atacados

Healthcare (1)

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingInformation ServicesEducational ServicesHealthCare & Social AssistancePublic AdministrationElectrical&Electronical ManufacturingElectrical Equipment, Appliance, and Component ManufacturingData Processing ServicesOther Information Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com