Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

Fmr Sec of State Mike Pompeo issues a frightening warning, says CCP has invaded ‘every major’ US university

January 29, 2023

Nadhim Zahawi: The chancellor who took one too many chances

January 29, 2023

Peskov: Vladimir Putin este deschis la discuții cu Olaf Scholz

January 29, 2023
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Sunday, January 29
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • Fmr Sec of State Mike Pompeo issues a frightening warning, says CCP has invaded ‘every major’ US university
  • Nadhim Zahawi: The chancellor who took one too many chances
  • Peskov: Vladimir Putin este deschis la discuții cu Olaf Scholz
  • Sunak government to unveil ‘virtual’ hospital wards plan for NHS
  • Top House Democrat Adam Smith criticizes general’s memo predicting war with China by 2025
  • Alaiba, despre reformele de la Ministerul Economiei: O eliberare masivă
  • Ambasador: SUA vor sprijini financiar Moldova pentru a trece de crize
  • Sunak faces political headache to replace Zahawi as supporters back Johnson for role
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » #StopRansomware: Daixin Team

#StopRansomware: Daixin Team

October 24, 20222 Mins Read Cybersecurity
Share
Facebook Twitter LinkedIn Pinterest Email

This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.

The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Department of Health and Human Services (HHS) are releasing this joint CSA to provide information on the “Daixin Team,” a cybercrime group that is actively targeting U.S. businesses, predominantly in the Healthcare and Public Health (HPH) Sector, with ransomware and data extortion operations.

This joint CSA provides TTPs and IOCs of Daixin actors obtained from FBI threat response activities and third-party reporting.

Cybercrime actors routinely target HPH Sector organizations with ransomware:

  • As of October 2022, per FBI Internet Crime Complaint Center (IC3) data, specifically victim reports across all 16 critical infrastructure sectors, the HPH Sector accounts for 25 percent of ransomware complaints.
  • According to an IC3 annual report in 2021, 649 ransomware reports were made across 14 critical infrastructure sectors; the HPH Sector accounted for the most reports at 148.

The Daixin Team is a ransomware and data extortion group that has targeted the HPH Sector with ransomware and data extortion operations since at least June 2022. Since then, Daixin Team cybercrime actors have caused ransomware incidents at multiple HPH Sector organizations where they have:

  • Deployed ransomware to encrypt servers responsible for healthcare services—including electronic health records services, diagnostics services, imaging services, and intranet services, and/or
  • Exfiltrated personal identifiable information (PII) and patient health information (PHI) and threatened to release the information if a ransom is not paid.

Daixin actors gain initial access to victims through virtual private network (VPN) servers. In one confirmed compromise, the actors likely exploited an unpatched vulnerability in the organization’s VPN server [T1190]. In another confirmed compromise, the actors used previously compromised credentials to access a legacy VPN server [T1078] that did not have multifactor authentication (MFA) enabled. The actors are believed to have acquired the VPN credentials through the use of a phishing email with a malicious attachment [T1598.002].

Read more at CISA

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

Joint Cyber Defense Collaborative Announces 2023 Planning Agenda

January 27, 2023 Cybersecurity

CISA, NSA, and MS-ISAC Release Advisory on the Malicious Use of RMM Software

January 27, 2023 Cybersecurity

Mayorkas and European Union Commissioner for Internal Market Breton Meet on Cyber Resilience Cooperation

January 27, 2023 Cybersecurity

Coast Guard Releases New Guide to Help Maritime Cybersecurity Assessments

January 27, 2023 Cybersecurity

U.S. Department of Justice Disrupts Hive Ransomware Variant

January 27, 2023 Cybersecurity

U.K. Warns of Targeted Phishing Attacks from Russia and Iran

January 26, 2023 Cybersecurity
Don't Miss
United Kingdom

Nadhim Zahawi: The chancellor who took one too many chances

By woe whJanuary 29, 20231

Sign up to the Inside Politics email for your free daily briefing on the biggest…

Peskov: Vladimir Putin este deschis la discuții cu Olaf Scholz

January 29, 2023

Sunak government to unveil ‘virtual’ hospital wards plan for NHS

January 29, 2023

Top House Democrat Adam Smith criticizes general’s memo predicting war with China by 2025

January 29, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Ambasador: SUA vor sprijini financiar Moldova pentru a trece de crize

January 29, 2023

Sunak faces political headache to replace Zahawi as supporters back Johnson for role

January 29, 2023

Nadhim Zahawi responds to sacking by Rishi Sunak: Read the letter in full

January 29, 2023

Boris Johnson tops list as MPs declare £8m in outside earnings

January 29, 2023

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2023 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.