
CrazyHunter Ransomware
CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

In July of 2025, large-scale exploitation of a vulnerability affecting Microsoft SharePoint servers was discovered by researchers. The campaign leverages a critical zero-day vulnerability in Microsoft SharePoint Server, tracked as CVE-2025-53770, to facilitate unauthorized remote code execution (RCE) on vulnerable on-premises servers.
Furthermore, the vulnerability allows attackers to exploit deserialization of untrusted data, granting unauthenticated access to SharePoint systems. The exploitation chain, dubbed "ToolShell," has been actively utilized in large-scale attacks, compromising over 85 SharePoint servers across 29 organizations, including multinational corporations and government entities. The impact of this vulnerability is quite significant, because it enables attackers to execute arbitrary code, access sensitive data, and potentially move laterally within the network of targeted victims. Its exploitation underscores the critical need for timely patching and robust security measures to protect enterprise infrastructures in modern environments. Intel 471 will continue to update this collection with pertinent info as research continues and new data is uncovered.
TITAN Reference:
Get your FREE Community Account today on the HUNTER Platform and get access to behavioral threat hunting content for your SIEM, EDR, NDR, and XDR platforms!

CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

DevMan Ransomware is a newly emerging ransomware operation observed in 2025 that has been assessed as a derivative of the DragonForce ransomware family.

Gootloader resurfaced with enhanced capabilities, building on the multi-stage loader malware first seen in 2020.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.