
CrazyHunter Ransomware
CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

Over last several years, clusters of English-speaking threat actors have conducted data breaches on a wide scale. These groups come from an online community known as Com or Community. In the beginning, these threat actors mostly focused mostly on harassing each other, stealing short usernames, cryptocurrency and cheating at games. But then they transitioned into serious data theft, extortion and ransomware. They’ve been intensely investigated by private companies and law enforcement, which have collaborated together to uncover some of their real-world identities and resulted in arrests. In this Studio 471, Michael Fletcher, a former Cybercrime Technical Analyst with the Australian Federal Police, describes the origins of The Com, the tactics used by these threat actors and why they pose a threat to organizations.
Participants:
Michael Fletcher, former Cybercrime Technical Analyst, Australian Federal Police
Jeremy Kirk, Executive Editor, Cyber Threat Intelligence, Intel 471

CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

DevMan Ransomware is a newly emerging ransomware operation observed in 2025 that has been assessed as a derivative of the DragonForce ransomware family.

Gootloader resurfaced with enhanced capabilities, building on the multi-stage loader malware first seen in 2020.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.