• Our Partners
  • CarePolicy
  • HomeCareConsulting
  • Digit9X
  • Home
  • Assisted Living
  • Elderly
  • Home Care Agency
  • Home Care Worker
  • Home Nursing
Menu
  • Home
  • Assisted Living
  • Elderly
  • Home Care Agency
  • Home Care Worker
  • Home Nursing
Home » Top ransomware groups targeting the healthcare sector
Elderly

Top ransomware groups targeting the healthcare sector

adminBy adminApril 25, 2025No Comments4 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


Why Health Care

Healthcare has always been an attractive target for threat actors, one of the top five industries targeted by ransomware.

why? Almost every organization operating in this sector is rich in highly sensitive information, including patient data, treatment documents, and financial records related to patient insurance. Furthermore, affected healthcare organizations are more likely to pay ransom, as network disruptions can cease completely, leading to patient death.

Proliferation as a ransomware service

Ransomware remains a tragedy, with Flashpoint analysts already collecting more than 1,462 ransomware attacks in 2025. It first emerged in 1989 and rapidly evolved from opportunistic attacks launched by lonely threat actors to a vast, institutional enterprise driven by the proliferation of readily available tools and services.

Today's ransomware landscape is dominated by the business model (RAAS) activities adopted by cybercriminals. Users purchase illegal licenses that allow them to access complex code, updates, customer support, keyloggers, miners, botnets and other tools.

Raas, which acts as a multiplier of force, significantly lowered the entry barrier, allowing even unsleashed attackers to leverage these complex tools against victims. Especially the healthcare sector.

From January to April 2025, FlashPoint observed a total of 181 medical victims. The next RAAS group is the most prolific.

giraffe

Qilin first appeared in July 2022. Originally operated under the name “Agenda”, Qilin became one of the most prolific ransomware groups in 2024. However, Qilin is known to target other industries, such as manufacturing, financial services and education. Between January and April 2025, Qilin ransomed 18 publicly disclosed victims in the health care sector.

Qilin ransomware, which is likely to have borne Russia, usually infects victims using spear phishing campaigns, remote monitoring and management (RMM) tools, and cobalt strike malware. Ransomware can be used to avoid detection using vulnerable SYS drivers and propagated through Psexec and SecureShell.
Like many other ransomware groups, Qilin is well known for its dual-terr technology, which involves requesting random payments to prevent data leaks in illegal forums and markets.

INC ransomware

INC has been operating since July 2023. Like Qilin, the group targets 18 publicly disclosed healthcare sector victims and uses double fear technology. The INC targets primarily the healthcare industry, but attack organizations in other fields, including education, technology and government, have been observed.

Initial infections usually date back to spearfishing lures, but Inc has recently utilized an exploit affecting CVE-2023-3519. This exploit can create stack-based buffer overflows and allow for the execution of arbitrary code.

A recent Verizon study shows ransomware is currently disproportionately affecting small and medium-sized businesses (SMBs). This is a trend seen in Inc's targeting as well. At the moment, many of the INC victims are small businesses with up to 1,000 employees, with the group focusing on targets of hospitals and health service providers.

Ransom Hub

A relatively new group, Ransomhub, first appeared in February 2024. Between January and April 2025, the group was responsible for targeting 16 publicly-published victims in the healthcare sector. Ransomhub also gained notoriety for its involvement in high-profile ransomware attacks.

Flashpoint analysts observe that Ransomhub gains initial access by leveraging CVE-2020-1472. This is a vulnerability that allows domain privileges to escalate and start control. No user interaction is required to take advantage of this exploit. It makes the ideal tool to throw away the requirements of social engineering.

Ransomhub's “Locker” ransomware is written in Golang and C++ and is supported by Windows, Linux, and ESXi. During the attack, FlashPoint observed the group that it used the incorrect cloud storage instance to target system backups.

Medusa

First introduced in June 2021, Medusa has become one of the top active ransomware groups targeting the healthcare sector, targeting 15 casualties between January and April 2025.

Medusa is best known for its rapid encryption and unique technology for spreading malware. The group made infamous in 2023 for attacking public schools. They demand a ransom of $1 million (USD).

To infect victims, Medusa relies on two early access vectors: phishing and vulnerability exploits. Medusa is known to take advantage of the Screenconnect vulnerability (CVE-2024-1709). This causes a remote attacker to start the setup wizard to create an administrative user and create a Fortinet EMS SQL Indection vulnerability (CVE-2023-48788) that allows SQL Quelie injection or manipulation.

Protect against ransomware using flashpoints

The relentless evolution and proliferation of ransomware, particularly through the RAAS model, continues to pose a major threat to the healthcare sector. Security teams need to be vigilant and proactive in their defense strategies as threat actors improve their tactics and leverage phishing and vulnerability exposure.

Understanding the specific techniques and advantageous access points of outstanding ransomware groups is an important first step in preventing and mitigating the potentially catastrophic effects of these attacks. Download the 2025 Ransomware Survival Guide and learn how Flashpoints provide a holistic approach to ransomware defense.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Supplements that are wary of severe drug-induced liver injuries in the United States

May 21, 2025

Why people who eat high protein should eat more fiber

May 21, 2025

Saudi Arabia's Healthcare Information Systems Market Forecast

May 13, 2025
Leave A Reply Cancel Reply

Top Posts

Calls to add climate change to all nurse training

June 2, 2025

How To Unlock A Windows PC Without The Password?

January 14, 2021
7.2

Best Chanel Perfume of 2024 – Top Chanel Fragrance Worth Buying

January 15, 2021

Is It Safe to Use an Old or Used Phone? Report Card

January 14, 2021
Don't Miss

Calls to add climate change to all nurse training

By adminJune 2, 2025

Climate change is “rapidly shaping” the clinical environments in which nursing staff work, a group…

Northern Ireland braces for ‘painful’ cuts to fund nurse pay deal

May 30, 2025

New study to investigate domestic abuse of nurses

May 30, 2025

WHO renews global nursing and midwifery strategy until 2030

May 29, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to HomeCareNews.us, your trusted source for comprehensive information on home healthcare services. Our mission is to empower individuals and families by providing accurate, up-to-date, and insightful information about essential home care services in USA.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Calls to add climate change to all nurse training

June 2, 2025

Home care providers use strategies to attract and retain the next generation of workers

May 30, 2025

Alliance appoints new leaders, Harmonycares expands C-Suite

May 30, 2025
Most Popular

Calls to add climate change to all nurse training

June 2, 2025

How To Unlock A Windows PC Without The Password?

January 14, 2021
7.2

Best Chanel Perfume of 2024 – Top Chanel Fragrance Worth Buying

January 15, 2021
  • Home
  • About Us
  • Advertise with Us
  • Contact us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 HomecareNews.US

Type above and press Enter to search. Press Esc to cancel.