Ransomware group

Crazyhunter ransomware: victims and leak site activity

The Crazyhunter ransomware group has listed 10 victims on its leak site since March 2025; its latest post is from 30 March 2025. Most affected countries: Taiwan and United States. Most targeted sector: Healthcare.

Total posts 10
First seen 2025-03-09
Latest post 2025-03-30
Countries hit 2

About Crazyhunter

CrazyHunter is a Go-based ransomware group that emerged in early 2025, derived from the open-source Prince encryptor, exclusively targeting Taiwanese organizations in healthcare, education, and industrial sectors using BYOVD techniques and tools like SharpGPOAbuse for lateral movement.

Leak site (Tor)
http://7i6sfmfvmqfaabjksckwrttu3nsbopl3xev2vbxbkghsivs5lqp4yeqd.onion:8088/api/v1/product?page=1&pageSize=20

Crazyhunter victims per year

10 2025

All 10 victims

Search every post in the full table.
Victim Country Sector Discovered
Zuni Data Taiwan Technology
Analog Integrations Corporation Taiwan Technology
Netronix Inc Taiwan Technology
Johnson Fitness United States Retail & E-Commerce
KD Panels Taiwan Manufacturing
Changhua Christian Hospital Taiwan Healthcare
Huacheng Electric Taiwan Manufacturing
Mackay Hospital Taiwan Healthcare
Asia University Hospital Taiwan Healthcare
Asia University Taiwan Education