
CrazyHunter Ransomware
CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

The advent of cybercrime-as-a-service – where cybercriminals create tools and products for use by other cybercriminals – has revolutionized online crime, allowing it to scale and become more effective. The discussions and products in underground forums and marketplaces can give clues as to how cybercriminals are exploiting and profiting. But these markets can be sprawling. Extracting useful cyber threat intelligence about emerging threats and monitoring the rise of novel threat actors can be a challenge. Michele Campobasso completed his doctoral thesis in 2024 about these issues while at the Eindhoven University of Technology. In this Studio 471, Campobasso shares his insight into these markets and how to maximize CTI collection.
Participants:
Michele Campobasso, PhD, Eindhoven University of Technology
Jeremy Kirk, Executive Editor, Cyber Threat Intelligence, Intel 471

CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

DevMan Ransomware is a newly emerging ransomware operation observed in 2025 that has been assessed as a derivative of the DragonForce ransomware family.

Gootloader resurfaced with enhanced capabilities, building on the multi-stage loader malware first seen in 2020.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.