logo

Ransomware gang 'CrazyHunter' Targets Critical Taiwanese Orgs

ID: 161838ba-d61a-5bb5-91df-2bbd4263cbb3

STIX ID: report--161838ba-d61a-5bb5-91df-2bbd4263cbb3

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-04-16

Date Updated: 2026-05-05

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

Trend Micro has identified CrazyHunter, a newly emerged ransomware group focusing on Taiwanese critical sectors (healthcare, education, manufacturing). The actor heavily leverages open-source tooling (Prince Ransomware Builder, ZammoCide, SharpGPOAbuse) and employs BYOVD (loading vulnerable signed drivers) to kill security processes, escalate privileges, and move laterally; the group has posted alleged victims to a leak site. Trend Micro recommends least privilege, MFA, patching, daily backups, auditing user permissions, and endpoint protections that detect/block unauthorized driver installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.