
CrazyHunter Ransomware
CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

Cobalt Strike (also known as CobaltStrike, BEACON) is a fully-featured and commerically available penetration testing tool offered by Washington, DC-based Strategic Cyber LLC. The tool is advertised for "Adversary Simulations and Red Team Operations" however its significant customization and capabilities have lead to its use by a wide variety of threat actors for a variety of motivations. Cobalt Strike also incorporates a variety of other post-exploitation tools, such as Mimikatz, in order to expand its functionality.
The toolset is a commercially available toolset, and as such its targeting will depend on the actor.
The toolset is capable of being delivered through a multitide of methods, including through malicious spam (malspam) campaigns, targeted spearphishing operations, or as a secondary infection.
The toolset can be run entirely in memory, or installed to disk.
Persistence can be established via a wide variety of methods, including scheduled tasks, Windows services, the use of various registry keys, WMI persistence through PowerShell and WMIC, use of local GPOs, Stickykeys through RDP, and Windows Startup.
The toolset is under active development, and features a number of unique modules which are termed "Aggressor Scripts."
Get the Free Hunt Packages!
Check Out Other Emerging Threats >

CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

DevMan Ransomware is a newly emerging ransomware operation observed in 2025 that has been assessed as a derivative of the DragonForce ransomware family.

Gootloader resurfaced with enhanced capabilities, building on the multi-stage loader malware first seen in 2020.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.