Ransomware Group intelligence
Crazyhunter
InactiveTrack Crazyhunter with 10 published victims and 2 known leak locations in a single intelligence view.
Overview
Crazyhunter is tracked by Breach House as a ransomware group with 10 published victims.
Taiwan, Province of China is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | 7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | 7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd.onion |
Top Activity Sectors (5)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Crazyhunter, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
What they do: crazyhunter exploits valid local accounts harvested during discovery to maintain persistence across systems.
What that means: Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1059.001 PowerShell Execution
What they do: crazyhunter executes PowerShell scripts to stage payloads and manipulate system processes during initial compromise.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: crazyhunter leverages registry run keys to ensure malware execution upon user logon or system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: crazyhunter disables antivirus tools and security software to evade detection before deploying ransomware.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1688 Safe Mode Boot Defense Impairment
What they do: crazyhunter forces safe mode boot configurations to bypass standard security controls during execution.
What that means: Adversaries may abuse Windows safe mode to disable endpoint defenses.
-
T1027.016 Junk Code Insertion Stealth
What they do: crazyhunter inserts junk code into legitimate binaries to evade static analysis and detection.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1135 Network Share Discovery Discovery
What they do: crazyhunter scans network shares using native tools to identify victim hosts and valuable data for targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: crazyhunter moves laterally via SMB/Windows Admin Shares to compromise additional networked machines.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: crazyhunter encrypts victim files using custom ransomware binaries, locking data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: crazyhunter halts system recovery by terminating critical services and processes to prevent restoration.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (2)
▼Software Crazyhunter has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (10)
Search, filter and paginate the victim timeline for Crazyhunter. Showing 1–10 of 10.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Zuni Data id18840 View details | Taiwan, Province of China | Other | ||
|
Taiwan - Zuni Data |
|||||
| Ransomware | Analog Integrations Corporation id18839 View details | Taiwan, Province of China | Services | ||
|
Taiwan - Analog Integrations Corporation |
|||||
| Ransomware | Netronix Inc id18837 View details | Taiwan, Province of China | Services | ||
|
Taiwan - Netronix Inc |
|||||
| Ransomware | Johnson Fitness id18632 View details | United States | Other | ||
|
Johnson Fitness |
|||||
| Ransomware | KD Panels id18454 View details | Taiwan, Province of China | Communication / Marketing | ||
|
Surface Material Supplier — Keding - the interior surface expert, committed to excellence in every detail. Featured Products: ECO+ Laminates, ECO+ Panels, KD Panels & KD Flooring. Guaranteed Quality. |
|||||
| Ransomware | Changhua Christian Hospital id18262 View details | Taiwan, Province of China | Healthcare / Pharma | ||
|
Changhua Christian Hospital |
|||||
| Ransomware | Huacheng Electric id18261 View details | Taiwan, Province of China | Other | ||
|
Due to confidentiality agreement, no details can be disclosed. |
|||||
| Ransomware | Mackay Hospital id18260 View details | Taiwan, Province of China | Healthcare / Pharma | ||
|
Mackay Hospital |
|||||
| Ransomware | Asia University Hospital id18259 View details | Taiwan, Province of China | Education | ||
|
Crazyhunter hacked into Asia University-www.asia.edu.tw from 2025.1.27 to 2025.1.29 |
|||||
| Ransomware | Asia University id18258 View details | Taiwan, Province of China | Education | ||
|
Crazyhunter hacked into Asia University-www.asia.edu.tw from 2025.1.27 to 2025.1.29 |
|||||