CrazyHunter Ransomware Group Targets Critical Sectors in Taiwan (Campaign)
ID: a25ccf88-59a7-5f20-b320-fdee497327ed
STIX ID: report--a25ccf88-59a7-5f20-b320-fdee497327ed
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-04-16
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
CrazyHunter is a newly observed ransomware group focusing on Taiwan’s critical sectors (healthcare, education, manufacturing). The group uses Bring Your Own Vulnerable Driver (BYOVD) techniques—notably abusing the Zemana zam64.sys driver via a tool called ZammoCide—to disable AV/EDR, leverages SharpGPOAbuse for lateral movement and privilege escalation, and deploys a heavily modified Prince ransomware (Go) alongside custom utilities (file.exe) and layered batch scripts to ensure encryption and exfiltration success.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
