
CrazyHunter Ransomware
CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

The Pysa Ransomware is a popular Ransomware-as-a-Service (RaaS) that has been observed operating since at least mid-2019. The name "Pysa" is possibly derived from the Zanzibari coin of the same name. The actors have also claimed the name to be an acronym for "Protect Your System Amigo."
It should be noted that the actors that use the Pysa RaaS also frequently engage in doxware operations where they exfiltrate data pre-encryption and threaten to disclose it on their leak site should the ransom not be paid.
Hi Company, Every byte on any types of your devices was encrypted.
Don't try to use backups because it were encrypted too. To get all your data back contact us:
aireyeric@protonmail.com
ellershaw.kiley@protonmail.com
-------------- FAQ: 1. Q: How can I make sure you don't fooling me? A: You can send us 2 files(max 2mb). 2. Q: What to do to get all data back? A: Don't restart the computer, don't move files and write us. 3. Q: What to tell my boss? A: Protect Your System Amigo.
Ref: https://dissectingmalwa.re/another-one-for-the-collection-mespinoza-pysa-ransomware.html
Get the Free Hunt Packages!
Check Out Other Emerging Threats >

CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

DevMan Ransomware is a newly emerging ransomware operation observed in 2025 that has been assessed as a derivative of the DragonForce ransomware family.

Gootloader resurfaced with enhanced capabilities, building on the multi-stage loader malware first seen in 2020.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.