logo

CrazyHunter Ransomware Attacking Healthcare Sector with Advanced Evasion Techniques

ID: adb862e8-9234-517c-a72f-90d0ea60ad2b

STIX ID: report--adb862e8-9234-517c-a72f-90d0ea60ad2b

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-07

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

CrazyHunter is a Go-based ransomware campaign actively targeting healthcare organizations (at least six known victims in Taiwan) that gains access via weak Active Directory credentials, spreads using SharpGPOAbuse, and escalates privileges and disables security products by exploiting a vulnerable Zemana antimalware driver. It uses a fast partial-file ChaCha20 encryption scheme with per-file keys protected by ECIES (renaming files with a .Hunter extension), maintains organized ransom negotiation channels and a data-leak site, and demonstrates tactics aimed at rapid compromise and evasion, posing significant patient-safety and data-exfiltration risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.