Actor Profile

🏹 crazyhunter — Ransomware

CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.

Classification

Ransomware

Leak-site victims

10
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (10)

VictimCountryPublishedDomain
Zuni Data TW 2025-03-30T22:26:08.744880+00:00 zunidata.com
Analog Integrations Corporation TW 2025-03-30T22:24:56.199636+00:00 analog.com.tw
Netronix Inc TW 2025-03-30T20:55:04.707003+00:00 netronixinc.com
Johnson Fitness US 2025-03-24T13:55:03.166834+00:00 johnsonfitness.com
KD Panels TW 2025-03-16T21:48:52.798906+00:00 kdpanels.com
Changhua Christian Hospital TW 2025-03-09T07:14:50.423741+00:00 cch.org.tw
Huacheng Electric TW 2025-03-09T07:13:38.960530+00:00 huachengsz.com
Asia University Hospital TW 2025-03-09T07:11:10.595296+00:00 asia.edu.tw
Asia University TW 2025-03-09T07:09:58.547237+00:00 asia.edu.tw
Mackay Hospital TW 2025-03-09T07:12:27.972578+00:00 mmh.org.tw

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php