Threat actors targeting Healthcare
Part of Threatwake, a free morning threat-intelligence dashboard.
33 threat actor groups tracked in MITRE ATT&CK are documented as targeting healthcare, between them using 309 distinct ATT&CK techniques. 11 healthcare victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against healthcare
- T1059.001 · PowerShell (execution) — used by 24 of 33 healthcare actors (73%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 22 of 33 healthcare actors (67%)
- T1588.002 · Tool (resource-development) — used by 21 of 33 healthcare actors (64%)
- T1204.002 · Malicious File (execution) — used by 18 of 33 healthcare actors (55%)
- T1078 · Valid Accounts (stealth) — used by 17 of 33 healthcare actors (52%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 17 of 33 healthcare actors (52%)
- T1059.003 · Windows Command Shell (execution) — used by 16 of 33 healthcare actors (48%)
- T1071.001 · Web Protocols (command-and-control) — used by 15 of 33 healthcare actors (45%)
- T1082 · System Information Discovery (discovery) — used by 15 of 33 healthcare actors (45%)
- T1005 · Data from Local System (collection) — used by 14 of 33 healthcare actors (42%)
- T1021.001 · Remote Desktop Protocol (lateral-movement) — used by 14 of 33 healthcare actors (42%)
- T1036.005 · Match Legitimate Resource Name or Location (stealth) — used by 14 of 33 healthcare actors (42%)
Threat actor groups
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- Turla (also: IRON HUNTER, Group 88, Waterbug, WhiteBear) — 68 documented techniques
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- Scattered Spider (also: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944) — 64 documented techniques
- Wizard Spider (also: UNC1878, TEMP.MixMaster, Grim Spider, FIN12) — 64 documented techniques
- VOID MANTICORE (also: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma) — 63 documented techniques
- APT39 (also: ITG07, Chafer, Remix Kitten) — 53 documented techniques
- FIN13 (also: Elephant Beetle) — 53 documented techniques
- Leviathan (also: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK) — 50 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- Earth Lusca (also: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX) — 44 documented techniques
- LAPSUS$ (also: DEV-0537, Strawberry Tempest) — 43 documented techniques
- Fox Kitten (also: UNC757, Parisite, Pioneer Kitten, RUBIDIUM) — 41 documented techniques
- BRONZE BUTLER (also: REDBALDKNIGHT, Tick) — 40 documented techniques
- FIN6 (also: Magecart Group 6, ITG08, Skeleton Spider, TAAL) — 40 documented techniques
- Tropic Trooper (also: Pirate Panda, KeyBoy) — 40 documented techniques
- FIN8 (also: Syssphinx) — 36 documented techniques
- Aquatic Panda — 35 documented techniques
- TA505 (also: Hive0065, Spandex Tempest, CHIMBORAZO) — 34 documented techniques
- APT42 — 32 documented techniques
- Play — 26 documented techniques
- INC Ransom (also: GOLD IONIC) — 25 documented techniques
- APT19 (also: Codoso, C0d0so0, Codoso Team, Sunshop Group) — 21 documented techniques
- CURIUM (also: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc) — 19 documented techniques
- Molerats (also: Operation Molerats, Gaza Cybergang) — 16 documented techniques
- EXOTIC LILY — 15 documented techniques
- Tonto Team (also: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda) — 15 documented techniques
- APT18 (also: TG-0416, Dynamite Panda, Threat Group-0416) — 12 documented techniques
- FIN4 — 12 documented techniques
- Deep Panda (also: Shell Crew, WebMasters, KungFu Kittens, PinkPanther) — 10 documented techniques
- POLONIUM (also: Plaid Rain) — 7 documented techniques
- Winnti Group (also: Blackfly) — 6 documented techniques
- Orangeworm — 2 documented techniques
Ransomware groups currently hitting healthcare
11 victims claimed in the current feed.
- CRPxO — 6 victims
- incransom — 1 victim
- Deadlock — 1 victim
- termite — 1 victim
- Global Secret Group — 1 victim
- dragonforce — 1 victim
Latest healthcare security news
- Data breach at medical billing firm MCBS affects 1.26 million people
- China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Threat intelligence by sector
- Financial Services
- Government & Defense
- Technology
- Manufacturing
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.