Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware

Share:

​Microsoft says a ransomware affiliate it tracks as Vanilla Tempest now targets U.S. healthcare organizations in INC ransomware attacks.

INC Ransom is a ransomware-as-a-service (RaaS) operation whose affiliates have targeted public and private organizations since July 2023, including Yamaha Motor Philippines, the U.S. division of Xerox Business Solutions(XBS), and, more recently, Scotland’s National Health Service (NHS).

In May 2024, a threat actor called “salfetka” claimed to sell the source code of INC Ransom’s Windows and Linux/ESXi encrypter versions for $300,000 on the Exploit and XSS hacking forums.

Microsoft revealed on Wednesday that its threat analysts have observed the financially motivated Vanilla Tempest threat actor using INC ransomware for the first time in an attack on the U.S. healthcare sector.

During the attack, Vanilla Tempest gained network access through the Storm-0494 threat actor, who infected the victim’s systems with the Gootloader malware downloader.

Once inside, the attackers backdoored the systems with Supper malware and deployed the legitimate AnyDesk remote monitoring and MEGA data synchronization tools.

The attackers then moved laterally using Remote Desktop Protocol (RDP) and the Windows Management Instrumentation Provider Host to deploy INC ransomware across the victim’s network.

While Microsoft didn’t name the victim hit by the Vanilla Tempest-orchestrated INC ransomware healthcare attack, the same ransomware strain was linked to a cyberattack against Michigan’s McLaren Health Care hospitals last month.

The attack disrupted IT and phone systems, caused the health system to lose access to patient information databases, and forced it to reschedule some appointments and non-emergent or elective procedures “out of an abundance of caution.”

Who is Vanilla Tempest?

Active since at least early June 2021, Vanilla Tempest (previously tracked as DEV-0832 and Vice Society) has frequently targeted sectors, including education, healthcare, IT, and manufacturing, using various ransomware strains such as BlackCat, Quantum Locker, Zeppelin, and Rhysida.

While active as Vice Society, the threat actor was known for using multiple ransomware strains during attacks, including Hello Kitty/Five Hands and Zeppelin ransomware.

CheckPoint linked Vice Society with the Rhysida ransomware gang in August 2023, another operation known for targeting healthcare, which tried to sell patient data stolen from Lurie Children’s Hospital in Chicago.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:12 am, Jan 26, 2025
weather icon 2°C
L: -0° | H: 3°
scattered clouds
Humidity: 80 %
Pressure: 1007 mb
Wind: 3 mph WSW
Wind Gust: 9 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 30%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:47 am
Sunset: 4:38 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
-0° | 3°°C 1 mm 100% 19 mph 93 % 1006 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 8°°C 1 mm 100% 22 mph 90 % 984 mb 0 mm/h
Tue Jan 28 9:00 pm
weather icon
7° | 9°°C 1 mm 100% 21 mph 86 % 996 mb 0 mm/h
Wed Jan 29 9:00 pm
weather icon
5° | 7°°C 1 mm 100% 15 mph 93 % 1001 mb 0 mm/h
Thu Jan 30 9:00 pm
weather icon
3° | 6°°C 0.93 mm 93% 10 mph 95 % 1023 mb 0 mm/h
Today 6:00 am
weather icon
2° | 4°°C 0 mm 0% 9 mph 81 % 1006 mb 0 mm/h
Today 9:00 am
weather icon
4° | 5°°C 0 mm 0% 14 mph 77 % 1003 mb 0 mm/h
Today 12:00 pm
weather icon
6° | 6°°C 0 mm 0% 17 mph 81 % 997 mb 0 mm/h
Today 3:00 pm
weather icon
5° | 5°°C 1 mm 100% 19 mph 93 % 990 mb 0 mm/h
Today 6:00 pm
weather icon
8° | 8°°C 1 mm 100% 14 mph 84 % 988 mb 0 mm/h
Today 9:00 pm
weather icon
9° | 9°°C 0 mm 0% 16 mph 79 % 986 mb 0 mm/h
Tomorrow 12:00 am
weather icon
8° | 8°°C 1 mm 100% 20 mph 90 % 979 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 7°°C 1 mm 100% 14 mph 77 % 982 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,743.84
0.20%
Ethereum(ETH)
€3,170.69
1.06%
XRP(XRP)
€2.97
0.16%
Tether(USDT)
€0.95
-0.01%
Solana(SOL)
€243.50
2.23%
Dogecoin(DOGE)
€0.336884
1.13%
USDC(USDC)
€0.95
-0.01%
Shiba Inu(SHIB)
€0.000019
0.07%
Pepe(PEPE)
€0.000014
-0.40%
Peanut the Squirrel(PNUT)
€0.341643
3.03%
Scroll to Top