HomeSecurityRoyal ransomware: Attacks healthcare organizations

Royal ransomware: Attacks healthcare organizations

The U.S. Department of Health and Human Services has issued a new warning to the nation's healthcare organizations about ongoing attacks by a relatively new entity, Royal ransomware.

See also: CommonSpirit Health: Ransomware attack led to data breach

The Healthcare Cybersecurity Coordination Center (HC3) revealed in an analyst notepublished on Wednesday that Royal ransomware is behind multiple attacks against US healthcare organizations.

US royal ransomware attacks

Sharp increase in activity since September


Unlike most active ransomware operations, Royal does not operate as a Ransomware-as-a-Service, but is a private group without partners.

Since September 2022, the operators of the Royal ransomware have been intensifying their activities, months after they were first detected in January 2022.
While initially using decryptors from other gangs such as BlackCat, they quickly switched to using their own encryptors. The first was Zeon, which created ransom notes similar to the Conti ransomware.

However, since mid-September 2022, the ransomware gang has rebranded itself as “Royal” and is using this name in the ransom notes it leaves to victims. These ransom notes are created by a new encryptor.

Royal Operation

The group uses social engineering tactics to trick victims into installing software that will give them remote access. This will happen after phishing attacks where attackers impersonate software providers and food delivery services.

Once their target is “infected,” the group encrypts the victims’ systems. Then comes the ransom demands, which range from $250,000 to $2 million.

Another of Royal’s unusual tactics is the use of hacked Twitter. Through these, they send information about the compromised targets to journalists in order to get coverage of the attack by the news media and put additional pressure on their victims.
These tweets will be sent to journalists and business owners, containing a link to the leaked data that was allegedly stolen from the victims’ networks before the encryption.

See also: CloudSEK: Claims to have been hacked by cybersecurity company

Royal ransomware: Attacks healthcare organizations

Healthcare Attacks

In addition to Royal, the U.S. federal government has warned of other ransomware groups known to target healthcare organizations.
The U.S. Department of Health and Human Services (HHS) said that the Venus ransomware is targeting healthcare organizations in the country.

Previous alerts targeting the Health and Public Health (HPH) sector reported that threat actors were using the Maui and Zeppelin.

In October, a joint advisory issued by CISA, the FBI, and HHS warned that the Daixin has also targeted the healthcare sector.

Finally, Professional Finance Inc (PFC) shared a data breach alert in July about a Quantum ransomware that occurred in late February and resulted in a data breach affecting 657 healthcare facilities.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS