CrazyHunter: The “Ruthless” Ransomware Stalking Healthcare
ID: 532b1443-853c-56f3-9f99-0ac0fbb145b4
STIX ID: report--532b1443-853c-56f3-9f99-0ac0fbb145b4
Feed Name: securityonline.info
Threat Score
CrazyHunter is a mid-2024 ransomware fork of Prince actively targeting healthcare organizations (notably in Taiwan), using weak Active Directory credentials and SharpGPOAbuse to spread via Group Policy, a BYOVD approach with a modified Zemana driver (zam64.sys) to kill antivirus, and a rapid partial ChaCha20 (1:2) encryption method to maximize impact; operators run a data-leak site and demand cryptocurrency ransoms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
