crazyhunter
First seen March 9, 2025Active10 claimed victims
The claims below are reproduced as posted by crazyhunter on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| Netronix Inc | March 30, 2025 | ransomware_live | — |
| Analog Integrations Corporation | March 30, 2025 | ransomware_live | — |
| Zuni Data | March 30, 2025 | ransomware_live | — |
| Johnson Fitness | March 24, 2025 | ransomware_live | — |
| KD Panels | March 16, 2025 | ransomware_live | — |
| Asia University | March 5, 2025 | ransomware_live | — |
| Asia University Hospital | March 5, 2025 | ransomware_live | — |
| Mackay Hospital | March 5, 2025 | ransomware_live | — |
| Huacheng Electric | March 5, 2025 | ransomware_live | — |
| Changhua Christian Hospital | March 5, 2025 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).