Skip to content

CrazyHunter

CrazyHunter is a Go-based ransomware family assessed as a fork or builder-derived variant of Prince ransomware.

Profile source: Mallory opens in a new tab

CrazyHunter

Family profile

CrazyHunter is a Go-based ransomware family assessed as a fork or builder-derived variant of Prince ransomware. It emerged by early 2025 and has been used primarily against organizations in Taiwan, with repeated targeting of the healthcare sector, including hospitals, and some activity against industrial organizations. The operation uses a data leak site to pressure victims, indicating double-extortion-style tactics in which stolen data may be exposed in addition to file encryption.

On Windows systems, CrazyHunter combines enterprise intrusion tradecraft with ransomware deployment. Reported initial access has included exploitation of weak Active Directory credentials, and at least one incident was reportedly linked to a USB device. After compromise, operators have used SharpGPOAbuse to weaponize Group Policy Objects for lateral movement and persistence across domain-joined environments.

A notable feature of CrazyHunter operations is the use of bring-your-own-vulnerable-driver techniques to disable security controls. The operators deploy a vulnerable Zemana anti-malware driver to elevate privileges and terminate defensive processes, including Microsoft Defender and Trend Micro components. The intrusion set has also used Donut-generated shellcode and in-memory loading to reduce detection, along with auxiliary tooling assessed to support file serving, monitoring, deletion, and exfiltration during extortion operations.

The ransomware encryptor is written in Go and uses ChaCha20 for file encryption with ECIES protecting per-file keys and nonces. Multiple reports describe partial encryption behavior inherited from the Prince codebase, enabling faster impact by encrypting portions of files rather than full contents. The malware enumerates drives, traverses directories, applies exclusion lists to avoid destabilizing the host, and drops a ransom note. Operationally, CrazyHunter appears to rely heavily on reused or publicly available tooling, but its combination of credential abuse, GPO-based propagation, BYOVD defense evasion, and rapid encryption makes it a significant threat to Windows enterprise environments, especially healthcare networks where downtime and data exposure create acute pressure to pay.

Capabilities

  • Byovd
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Privilege Escalation

Operational record

3
Indicators
1
YARA rules
1
Leak sites
0 available

Defense Evasion

  • Zemana Anti-Rootkit driver
  • av-1m.exe (AV bypass)
  • go.exe / go2.exe (BYOVD loader)

Offsec

  • Donut
  • Prince Ransomware
  • SharpGPOAbuse
  • bb.exe (shellcode loader)

Published indicators

Telegram

2 total
  • https://t.me/CrazyHuntersTeam
  • https://t.me/Magic13377

Tox

1 total
  • E8481B6E149862EEEA79668EBBC50B96A6B6529C5DDD905491E2F838EF7D174FB73DB97F1FFD

Reported operators

Threat actors

1 named in public reporting
CrazyHunter

CrazyHunter, a Go-developed ransomware, employs advanced encryption and delivery methods targeted against Windows-based machines. It uses a data leak site to publicize victim information.

MITRE ATT&CK

CrazyHunter in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.