
CrazyHunter Ransomware
CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

As the war in Ukraine rages on, unseen but related battles occur daily across the globe. These confrontations stem from pro-Russian hacktivist groups targeting countries that support Ukraine, likely with support from the Kremlin. These hacktivists have been targeting a wide swath of industries and sectors, including aviation, energy, financial, government and public safety, technology, media and telecommunications sectors.
Hacktivism is the combination of hacking (unauthorized access to or control over computer network security systems for some illicit purpose) and political activism. Because of this, hacktivists have social and political agendas as opposed to hackers who commit cyber crimes for profit and often times infamy. It should be noted that many pro-Russian hacktivists are also likely to be hackers responsible for attacks across enterprises and governments.
Pro-Russian hacktivist activity
The pro-Russian hacktivist groups targeting governments and organizations that oppose Russia's stance on the war in Ukraine have been observed using several cyber tactics, including DDoS attacks, network intrusion and stealing personally identifiable information (PII).
In July and August 2022, numerous hacktivist groups accelerated their nefarious activities. The most impactful Ukrainian-specific incidents conducted by major pro-Russian hacktivist groups detected by Intel 471 were:

On August 17, 2022, KillNet claimed responsibility for extensive cyberattacks in Estonia shortly after government officials decided to remove Soviet-era monuments near the border with Russia. KillNet also allegedly blocked access to over 200 private and Estonian state institutions, including banks, government organizations, payment systems and public services.
NoName057(16): This hacktivist group, the most active of the groups on this list, conducted multiple DDoS attacks against entities in Norway, prompted by the decision of Norwegian authorities to block Russian cargo to the Svalbard archipelago. In addition, members attacked numerous companies from the financial and government sectors in Lithuania, apparently due to the country's ban on transporting goods and cargo to the Kaliningrad region of Russia. The gang also conducted massive attacks on the Polish government and transportation sectors, including airports in Kraków, Warsaw and Wrocław, the gas pipeline EuRoPol, the logistics company PKP Cargo and defense weapon and military equipment provider Polski Holding Obronny. Last but by no means least, group members attacked various Finnish, Latvian and Polish government agencies all considered to be sympathetic to the Ukrainian effort. The graph below shows a breakdown of the impacted entities by country.

Due to the very nature of state-sponsored cyber attacks, there is limited conclusive evidence that the Kremlin is directing or supporting the aforementioned hacktivism. Although the link likely exists and state-sponsored hacking is nothing new, the Kremlin will be sure to distance itself from any malign activity so as not to risk breaching NATOs Collective Defence treaty, Article 5. In any case, companies, enterprises and governments should limit their attack surface, ensure that software patching is conducted routinely and invest in increased threat detection capabilities in the face of Russian cyber aggression.

CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

DevMan Ransomware is a newly emerging ransomware operation observed in 2025 that has been assessed as a derivative of the DragonForce ransomware family.

Gootloader resurfaced with enhanced capabilities, building on the multi-stage loader malware first seen in 2020.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.