Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Microsoft: US Healthcare Sector Targeted by INC Ransomware Affiliate

Microsoft has observed the threat actor Vanilla Tempest targeting US healthcare organizations with INC ransomware.

A threat actor has been observed using the INC (Inc Ransom) ransomware in attacks targeting organizations in the US healthcare sector, Microsoft warns.

A financially motivated cybercrime group that Microsoft tracks as Vanilla Tempest, the threat actor targets systems previously infected with the Gootloader malware, which it uses to expand its foothold on the compromised networks and deploy ransomware.

“Vanilla Tempest receives hand-offs from Gootloader infections by the threat actor Storm-0494, before deploying tools like the Supper backdoor, the legitimate AnyDesk remote monitoring and management (RMM) tool, and the MEGA data synchronization tool,” Microsoft revealed on X (formerly Twitter).

Next, the threat actor was seen abusing the Remote Desktop Protocol (RDP) to move laterally on the victim organization’s network, and employing the Windows Management Instrumentation (WMI) Provider Host to deploy the ransomware payload.

Vanilla Tempest, Microsoft says, has been active for at least two years, mainly targeting entities in the education, healthcare, IT, and manufacturing sectors.

According to available cybersecurity reports, Vanilla Tempest’s activity overlaps with that of Vice Society, which is also tracked as DEV-0832, and which has been active since at least June 2021. In 2022, the US government issued an alert on the group’s attacks on the US education sector.

Advertisement. Scroll to continue reading.

Although it uses multiple ransomware families in attacks, Vice Society is likely associated with the Rhysida ransomware gang, according to a Check Point report last year.

Previously, the threat actor was observed using various ransomware families in its attacks, including BlackCat, Rhysida, Quantum Locker, and Zeppelin.

The INC ransomware Vanilla Tempest has been deploying in recent attacks has been active for roughly a year, being offered under a ransomware-as-a-service (RaaS) model, which suggests that Vanilla Tempest is only an affiliate.

Previously, INC ransomware affiliates have claimed responsibility for cyberattacks on Access Sports, Xerox Business Solutions US, and Yamaha Motor Philippines.

Related: Ransomware Group Leaks Data Allegedly Stolen From Kawasaki Motors

Related: City of Columbus Sues Researcher Who Disclosed Impact of Ransomware Attack

Related: Indianapolis Low-Income Housing Agency Hit by Ransomware

Related: Ransomware Attack Hits PNG Finance Ministry

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.