• Our Partners
  • CarePolicy
  • HomeCareConsulting
  • Digit9X
  • Home
  • Assisted Living
  • Elderly
  • Home Care Agency
  • Home Care Worker
  • Home Nursing
Menu
  • Home
  • Assisted Living
  • Elderly
  • Home Care Agency
  • Home Care Worker
  • Home Nursing
Home » Microsoft warns of new INC ransomware targeting US healthcare sector
Elderly

Microsoft warns of new INC ransomware targeting US healthcare sector

adminBy adminSeptember 19, 2024No Comments2 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 19, 2024Ravi LakshmananHealthcare/Malware

INC Ransomware

Microsoft has revealed that financially motivated threat actors have been observed targeting the US healthcare sector for the first time using ransomware dubbed INC.

The tech giant’s threat intelligence team is tracking the campaign under the name Vanilla Tempest, formerly known as DEV-0832.

“Vanilla Tempest takes handoff from a GootLoader infection by threat actor Storm-0494, and subsequently deploys tools such as the Supper backdoor, the legitimate AnyDesk remote monitoring and management (RMM) tool, and the MEGA data sync tool,” said a series of posts shared on X.

In the next step, the attackers perform lateral movement over Remote Desktop Protocol (RDP) and deploy the INC ransomware payload using the Windows Management Instrumentation (WMI) Provider Host.

According to the Windows maker, Vanilla Tempest has been active since at least July 2022, with previous attacks targeting the education, healthcare, IT and manufacturing sectors using various ransomware families, including BlackCat, Quantum Locker, Zeppelin and Rhysida.

Cybersecurity

Notably, the threat actor is also being tracked under the name Vice Society, which is known for leveraging existing lockers to carry out attacks rather than building their own custom versions.

The move comes as ransomware groups such as BianLian and Rhysida have been observed increasingly using Azure Storage Explorer and AzCopy to exfiltrate sensitive data from compromised networks in a bid to evade detection.

“This tool, used to manage Azure storage and the objects within it, is being repurposed by threat actors for large-scale data transfers to cloud storage,” modePUSH researcher Britton Manahan said.

Did you find this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Saudi Arabia's Healthcare Information Systems Market Forecast

May 13, 2025

McHenry County College will host the 5th Annual Healthcare Industry Forum

May 12, 2025

HSCC warns about an increasing number of cybersecurity threats to resource-trained healthcare providers and encourages immediate action

May 12, 2025
Leave A Reply Cancel Reply

Top Posts

Kim Leadbeater Confirms Support For Marie Curie Amendment

May 13, 2025

How To Unlock A Windows PC Without The Password?

January 14, 2021
7.2

Best Chanel Perfume of 2024 – Top Chanel Fragrance Worth Buying

January 15, 2021

Is It Safe to Use an Old or Used Phone? Report Card

January 14, 2021
Don't Miss

Former CNO appointed professor of nursing

By adminMay 13, 2025

The former national chief nursing officer (CNO) for England has been appointed as professor of…

Government to ban overseas care worker recruitment

May 12, 2025

RCN chief warns of potential strike action over pay this year

May 12, 2025

NMC begins search for permanent chief executive

May 12, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to HomeCareNews.us, your trusted source for comprehensive information on home healthcare services. Our mission is to empower individuals and families by providing accurate, up-to-date, and insightful information about essential home care services in USA.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Kim Leadbeater Confirms Support For Marie Curie Amendment

May 13, 2025

Saudi Arabia's Healthcare Information Systems Market Forecast

May 13, 2025

Former CNO appointed professor of nursing

May 13, 2025
Most Popular

Kim Leadbeater Confirms Support For Marie Curie Amendment

May 13, 2025

How To Unlock A Windows PC Without The Password?

January 14, 2021
7.2

Best Chanel Perfume of 2024 – Top Chanel Fragrance Worth Buying

January 15, 2021
  • Home
  • About Us
  • Advertise with Us
  • Contact us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 HomecareNews.US

Type above and press Enter to search. Press Esc to cancel.