Ransomware gang 'CrazyHunter' Targets Critical Taiwanese Orgs
ID: 161838ba-d61a-5bb5-91df-2bbd4263cbb3
STIX ID: report--161838ba-d61a-5bb5-91df-2bbd4263cbb3
Feed Name: Dark Reading
Date Published: 2025-04-16
Date Updated: 2026-05-05
Author: Alexander Culafi, Senior News Writer, Dark Reading
Trend Micro has identified CrazyHunter, a newly emerged ransomware group focusing on Taiwanese critical sectors (healthcare, education, manufacturing). The actor heavily leverages open-source tooling (Prince Ransomware Builder, ZammoCide, SharpGPOAbuse) and employs BYOVD (loading vulnerable signed drivers) to kill security processes, escalate privileges, and move laterally; the group has posted alleged victims to a leak site. Trend Micro recommends least privilege, MFA, patching, daily backups, auditing user permissions, and endpoint protections that detect/block unauthorized driver installations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
