BreachCensus

crazyhunter

First seen March 9, 2025Active10 claimed victims

The claims below are reproduced as posted by crazyhunter on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Netronix IncMarch 30, 2025ransomware_live
Analog Integrations CorporationMarch 30, 2025ransomware_live
Zuni DataMarch 30, 2025ransomware_live
Johnson FitnessMarch 24, 2025ransomware_live
KD PanelsMarch 16, 2025ransomware_live
Asia UniversityMarch 5, 2025ransomware_live
Asia University HospitalMarch 5, 2025ransomware_live
Mackay HospitalMarch 5, 2025ransomware_live
Huacheng ElectricMarch 5, 2025ransomware_live
Changhua Christian HospitalMarch 5, 2025ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).