HomeSecurityRansomware groups target cancer centers

Ransomware groups target cancer centers

An attack on a US cancer center this month by an unknown ransomware group has caused a stir in the healthcare sector over the threat actor's "rarely used and highly effective" techniques.

See also: BlackCat ransomware: Hackers threaten to leak Reddit data

ransomware

While the group, which calls itself TimisoaraHackerTeam (THT), is not widely known, it has a history of attacking medical facilities by exploiting known vulnerabilities and using a specific approach to minimize detection.

In an alert (PDF) about the attack on a cancer center this month, the Department of Health and Human Services' Healthcare Cybersecurity Coordination Center (HC3) said the THT group was first discovered by researchers in July 2018 and has been targeting healthcare organizations around the world.

HC3 did not name THT's latest target, but said the attack on the cancer center "rendered its digital services unavailable, compromised patients , and significantly reduced the medical center to provide treatment to patients."

Research into THT’s tactics, techniques, and procedures (TTPs) suggested a connection between it and suspected Chinese malware groups, including DeepBlueMagic and APT41, which have a history of targeting healthcare organizations. It is unclear, however, whether the groups shared members or simply used similar methods.

See also: US: Offering $10 million reward for information on Clop ransomware gang

What is a LOTL attack?

Adopting a “living-off-the-land” (LOTL) approach allowed teams to encrypt files without being detected by security solutions. A LOTL attack, sometimes described as a fileless malware attack, is a type of technique that uses applications that are considered friendly and are not marked as malicious. For example, an attack might involve Windows tools, such as PowerShell and Windows Management Instrumentation (WMI), to open a system to a malware attack.

HC3 reported that THT's ransomware attacks appear to target healthcare organizations with medium to large servers, and that the group often used common vulnerability exploits (CVEs) against vulnerable VPNs to gain initial remote access to the victim's network.

See also: Des Moines: Iowa's largest school district falls victim to ransomware

Ransomware groups target cancer centers

THT team exploits unpatched bug cases

This is what happened in THT's latest attack on the cancer center, where it targeted Fortinet's FortiOS SSL-VPN to exploit CVE-2022-42475, a heap-based buffer overflow vulnerability that allows remote attackers to execute code or commands using specially crafted requests.

TimisoaraHackerTeam is named after the Romanian city of Timisoara, and researchers say that examination of THT's source code suggests it was created by Romanian speakers.

According to HC3's disclosure, an attack on a French hospital in April 2021 was attributed to THT, while the most notorious attack carried out by DeepBlueMagic was on the Hillel Yaffe Medical Center in Israel in August 2021.

Source of information: scmagazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS