Uptime Hamster: 10d 18h 23mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21

BushidoUK ToolMatrix CommunityReports: CR-011-CrazyHunter-March-2025

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United Kingdom
Sector
Healthcare
Confianza
high
100
Prioridad analitica
Alta

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

13IOCs
0TTPs
bushidoukActor
United KingdomPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Key Points

  • Source: CommunityReports/CR-011-CrazyHunter-March-2025.md
  • BushidoUK Tool Matrix

CommunityReports: CR-011-CrazyHunter-March-2025.md

Recurso del BushidoUK Ransomware Tool Matrix - CommunityReports.

Community Report 011 - CrazyHunter March 2025

Contributor Details

- Real Name: N/A

- Online Handle / Links to profiles: @knappresearchlb

- Employer: Private, Threat Intelligence Lead

- Affiliations: Ransom-ISAC

---

Adversary

- Named adversary: CrazyHunter Ransomware

---

Incident Details

- Time of Incident: February 2025

- Victim Sector: Healthcare

- Victim Country: Taiwan

- Victim Size: 1000-10000

- Victim Name: Mackay Memorial Hospital

---

Observed Tools

DiscoveryRMM ToolsDefense EvasionCredential TheftOffSecNetworkingLOLBASExfiltration
(zam64.sys) vulnerable Zemana Anti-Logger kernel driverSharpGPOAbusefile.exe - a tool capable of hosting/setting up the victim’s machine as a file server or to monitor for files with specific extensions in the specified directory. Based on its capabilities, it is almost certain that this tool is used for data exfiltration
go.exe (malware written in Go programming language designed to load a vulnerable version of Zemana Anti-Logger kernel driver, zam64.sys)Prince Ransomware
go2.exe (malware written in Go programming language designed to load a vulnerable version of Zemana Anti-Logger kernel driver, zam64.sys)Donut - a tool that generates shellcode from PE files
av-1m.exe - an AV bypass toolbb.exe - a shellcode loader which loaded crazyhunter.sys

---

Indicators of Compromise (IOCs)

File NameSha256
bb.exe2cc975fdb21f6dd20775aa52c7b3db6866c50761e22338b08ffc7f7748b2acaa
crazyhunter.exef72c03d37db77e8c6959b293ce81d009bf1c85f7d3bdaa4f873d3241833c146b
crazyhunter.sys5316060745271723c9934047155dae95a3920cb6343ca08c93531e1c235861ba
file.exe14359f54d49799c713c2a8cc0c19a88392a0c6ad2c383494023008326cd0ba15
go.exe754d5c0c494099b72c050e745dde45ee4f6195c1f559a0f3a0fddba353004db6
go2.exe983f5346756d61fec35df3e6e773ff43973eb96aabaa8094dcbfb5ca17821c81
go3.exef72c03d37db77e8c6959b293ce81d009bf1c85f7d3bdaa4f873d3241833c146b
gpo.exe512f785d3c2a787b30fa760a153723d02090c0812d01bb519b670ecfc9780d93
ru.batd1081c77f37d080b4e8ecf6325d79e6666572d8ac96598fe65f9630dda6ec1ec
zam64.sys2bbc6b9dd5e6d0327250b32305be20c89b19b56d33a096522ee33f22d8c82ff1
bb2.zipbdfc66266a2a19fc3d5dccef3eefe4c0ee928ba5b7abad60bc320218b2082fea

#### Any Related Sources

- CrazyHunter: The Rising Threat of Open-Source Ransomware

- Donut OST - https://github.com/TheWover/donut/tree/master

- SharpGPOAbuse - https://github.com/FSecureLABS/SharpGPOAbuse

Date PublishedReport
31/03/2025https://labs.withsecure.com/publications/crazyhunter-ransomware

``mermaid

flowchart TD;

A[CrazyHunter Ransomware] -->|target| B(Geo: Taiwan

Sector: Healthcare

Size: 5000-8000 Employees);

B --> C{Tools};

C -->|Defense Evasion| F[4];

C -->|OffSec| H[4];

C -->|Exfiltration| K[1];

``

Referencias

Diamond Model

Adversary
bushidouk
Ver perfil →
Victim
BushidoUK ToolMatrix CommunityReports: CR-011-CrazyHunter-March-2025
United Kingdom
Capability
Report
Infrastructure
labs.withsecure.com

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
File zam64.sys Artefacto observado VT OffSec SOCRadar
File file.exe Artefacto observado VT OffSec SOCRadar
File go.exe Artefacto observado VT OffSec SOCRadar
File go2.exe Artefacto observado VT OffSec SOCRadar
File av-1m.exe Artefacto observado VT OffSec SOCRadar
File bb.exe Artefacto observado VT OffSec SOCRadar
File crazyhunter.sys Artefacto observado VT OffSec SOCRadar
File crazyhunter.exe Artefacto observado VT OffSec SOCRadar
File go3.exe Artefacto observado VT OffSec SOCRadar
File gpo.exe Artefacto observado VT OffSec SOCRadar
File ru.bat Artefacto observado VT OffSec SOCRadar
File bb2.zip Artefacto observado VT OffSec SOCRadar
Domain labs.withsecure.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United Kingdom → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes