logo

Open-Source Builder for Prince Ransomware Discovered Available on GitHub

ID: e0c308c8-d373-5dcf-ac2f-e367970a1ae8

STIX ID: report--e0c308c8-d373-5dcf-ac2f-e367970a1ae8

Feed Name: Halcyon Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-04-28

...
...

The report describes the emergence of the open-source "Prince Ransomware" builder and variants, and documents a real-world incident where a Prince-built payload called CrazyHunter—delivered via a malicious package—encrypted over 600 devices across two hospital branches in Taiwan. The attack leveraged lateral movement via GPO abuse, a Bring-Your-Own-Vulnerable-Driver (zam64.sys) to disable defenses, AV-disabling binaries (go.exe/go2.exe), and a data exfiltration component, illustrating how accessible builders can rapidly democratize ransomware operations and increase attack volume against smaller organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.