Open-Source Builder for Prince Ransomware Discovered Available on GitHub
ID: e0c308c8-d373-5dcf-ac2f-e367970a1ae8
STIX ID: report--e0c308c8-d373-5dcf-ac2f-e367970a1ae8
Feed Name: Halcyon Blog
The report describes the emergence of the open-source "Prince Ransomware" builder and variants, and documents a real-world incident where a Prince-built payload called CrazyHunter—delivered via a malicious package—encrypted over 600 devices across two hospital branches in Taiwan. The attack leveraged lateral movement via GPO abuse, a Bring-Your-Own-Vulnerable-Driver (zam64.sys) to disable defenses, AV-disabling binaries (go.exe/go2.exe), and a data exfiltration component, illustrating how accessible builders can rapidly democratize ransomware operations and increase attack volume against smaller organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
