CrazyHunter Ransomware Attacking Healthcare Sector with Advanced Evasion Techniques
CrazyHunter ransomware has emerged as a significant threat targeting healthcare organizations and sensitive medical infrastructure. Developed in the Go programming language, this malware employs advanced encryption methods and delivery mechanisms…
CrazyHunter ransomware has emerged as a significant threat targeting healthcare organizations and sensitive medical infrastructure. Developed in the Go programming language, this malware employs advanced encryption methods and delivery mechanisms designed to bypass modern security defenses.
Healthcare institutions in Taiwan have been targeted, with at least six organizations experiencing attacks. The critical nature of medical services and the vast quantities of sensitive patient information make these institutions valuable targets for extortion.
CrazyHunter demonstrates tactical sophistication and operational maturity. It begins with an initial compromise through Active Directory exploitation, leveraging weak domain account passwords. Once inside a network, attackers use SharpGPOAbuse to distribute the ransomware payload via Group Policy Objects, enabling rapid propagation across connected systems.
The malware executes operations to disable security systems , encrypt critical files, and maintain operational secrecy throughout the attack lifecycle.
CrazyHunter ransomware has emerged as a significant threat targeting healthcare organizations and sensitive medical infrastructure.
CrazyHunter employs multiple antivirus-disabling components, sophisticated memory-based execution techniques, and backup encryption mechanisms to ensure encryption success even if primary deployment methods fail. It utilizes a bring-your-own-vulnerable-driver approach, exploiting a legitimate but vulnerable Zemana antimalware driver version 2.18.371.0 to elevate privileges and terminate security software processes.
Encryption Mechanisms and Data Protection Strategy
The malware uses a hybrid encryption architecture combining symmetric and asymmetric cryptographic methods. It employs the ChaCha20 stream cipher as its primary encryption algorithm, operating with a 1:2 encryption ratio to accelerate the process. Encrypted files receive a .Hunter extension and contain the ECIES-encrypted key, nonce, and partially encrypted file content.
The encryption mechanism protects its cryptographic keys through the Elliptic Curve Integrated Encryption Scheme (ECIES). Each file's unique ChaCha20 keys and nonces are encrypted using the attacker’s ECIES public key, making decryption impossible without the corresponding private key.
Structured ransom negotiation channels, including dedicated email addresses and Telegram communication channels, indicate an organized criminal operation with established victim engagement processes.
Based on reporting by Cyber Security News.
