
CrazyHunter Ransomware
CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

In late September 2022 Microsoft released information relating to 2 previously unknown zero-day vulnerabilities collectively known as "ProxyNotShell" affecting Microsoft Exchange. These vulnerabilities were noted by security researchers to be actively exploited in the wild. The two vulnerabilities (CVE-2022-41040 and CVE-2022-41082) are known to impact Microsoft Exchange Server 2013, 2016, and 2019. ProxyNotShell, according to Microsoft, is two vulnerabilities with "... the first vulnerability, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, while the second, identified as CVE-2022-41082, allows remote code execution (RCE) when PowerShell is accessible to the attacker." Microsoft does note that successful exploitation does require authentication to trigger either vulnerability.
Owing to the fact that the vulnerabilities associated with ProxyNotShell are being actively exploited in the wild, Cyborg Security has released several hunt packages to the community in order to detect behaviors known to be associated with the attack. Sign up for a free Community HUNTER Account to get exclusive access to these hunt packages today!
Get the Free Hunt Packages!
Check Out Other Emerging Threats >

CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

DevMan Ransomware is a newly emerging ransomware operation observed in 2025 that has been assessed as a derivative of the DragonForce ransomware family.

Gootloader resurfaced with enhanced capabilities, building on the multi-stage loader malware first seen in 2020.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.