CrazyHunter Ransomware Targets Healthcare Sector Using Sophisticated Evasion Tactics
A new ransomware variant, CrazyHunter, poses a significant threat to the healthcare sector, employing advanced anti-malware evasion techniques and rapid network propagation. Trellix has been monitoring this threat and reports that it represents an…
A new ransomware variant, CrazyHunter, poses a significant threat to the healthcare sector, employing advanced anti-malware evasion techniques and rapid network propagation. Trellix has been monitoring this threat and reports that it represents an evolution in cybercriminal tactics targeting medical institutions.
CrazyHunter is derived from the Prince ransomware builder, developed in the Go programming language, and focuses on Windows systems. It introduces advancements in network compromise techniques and defense evasion mechanisms.
The primary targets have been healthcare organizations in Taiwan, with six confirmed compromised institutions. The attackers exploit the critical nature of healthcare services and the sensitive patient data these organizations maintain. Hospital downtime creates immense pressure on victims to pay ransoms quickly.
CrazyHunter attacks follow a four-stage approach, exploiting weak passwords in Active Directory infrastructure to gain domain-level access. The ransomware uses SharpGPOAbuse to distribute malicious payloads through Group Policy Objects, enabling rapid network propagation.
Trellix has been monitoring this threat and reports that it represents an evolution in cybercriminal tactics targeting medical institutions.
An advanced privilege escalation technique is employed using a bring-your-own-vulnerable-driver (BYOVD) attack with a weaponized version of the Zemana anti-malware driver (zam64.sys). This allows attackers to operate at the kernel level, terminating security software before deploying the encryption payload.
CrazyHunter deploys multiple components to ensure successful encryption. The attack chain includes specialized executables (go.exe and go2.exe) to neutralize security defenses, followed by the primary ransomware payload (go3.exe). A Donut Loader (bb.exe) enables fileless execution by loading shellcode directly into memory.
The ransomware uses the ChaCha20 stream cipher for file encryption with a unique 1:2 pattern. Encryption keys are protected using Elliptic Curve Integrated Encryption Scheme (ECIES), ensuring victims cannot decrypt files without the attacker's private key. Encrypted files receive the Hunter extension.
Organizations must enforce multi-factor authentication and strictly control Group Policy Object modification rights. Trellix has implemented protection measures against CrazyHunter, providing customers with robust defense.
As ransomware operators continue developing sophisticated evasion techniques, healthcare organizations should prioritize cybersecurity investments to protect patient data and maintain operations.
Based on reporting by GBHackers.
