
CrazyHunter Ransomware
CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

Introduction
With the Russian army reportedly experiencing heavy casualties in the war with Ukraine, the Kremlin is seemingly doubling down on its war commitment by expanding its number of conscripted troops. On September 21, 2022, Russian President Vladimir Putin announced a so-called "partial" military mobilization in Russia, including summoning more than 300,000 people for military service, ostensibly to bolster their war effort.
By another name, this "partial" military mobilization is called "conscription," the state-mandated enlistment of people into a military or national service. Putin's signed order only called up military reservists with combat or service experience. However, Russian media reports have described attempts to round up men without relevant experience, including those ineligible for service due to medical reasons.
Underground forum chatter offers unique war mobilization perspectives
Following the mobilization announcement, Russian-speaking actors started numerous threads on a plethora of underground cybercrime forums to discuss the situation. Intel 471 reviewed the relevant chatter and documented the perspectives and reactions of underground actors regarding the mobilization. Some of the key points and anecdotal thoughts reveal:
Actors find illegal avenues to help conscripts
Recognizing the dire situation, dozens of Russian-speaking actors capitalized on these trends and started offering services to help conscripts dodge military mobilization for a price, including:
Specific offers made by actors to avoid conscription
Intel 471's research has highlighted the many conscription-avoidance offers made by Russian-speaking actors across underground forums. Some of the more credible examples are below. The names of rivers are used as monikers and they are not the actors' real handles. These offers include:
With global events come underground opportunities
While it is impossible to know how many takers these offers got, young Russian men from all walks of life have left the country. In the wake of Putin's mobilization order, more than 194,000 Russian nationals fled to neighboring Georgia and Finland. So it is highly likely that law-abiding Russian men took advantage of some of these offers from Russian-speaking underground actors to escape.
Interestingly, in the face of a historical conflict, Russian-speaking actors stay true to their colors. They dislike the army but, if called, would apparently serve in the war because of their allegiance to the Russian state. But financially motivated underground actors are always just that, financially motivated, devising new ways to make a profit or invent a scheme to make money. In that sense, their skills easily transfer from cybercrime to one geopolitical event to another, in this case, war profiteering.

CrazyHunter is a ransomware campaign targeting healthcare that weakens endpoint defenses and escalates privileges before encrypting systems at scale.

DevMan Ransomware is a newly emerging ransomware operation observed in 2025 that has been assessed as a derivative of the DragonForce ransomware family.

Gootloader resurfaced with enhanced capabilities, building on the multi-stage loader malware first seen in 2020.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.