Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware

Share:

​Microsoft says a ransomware affiliate it tracks as Vanilla Tempest now targets U.S. healthcare organizations in INC ransomware attacks.

INC Ransom is a ransomware-as-a-service (RaaS) operation whose affiliates have targeted public and private organizations since July 2023, including Yamaha Motor Philippines, the U.S. division of Xerox Business Solutions(XBS), and, more recently, Scotland’s National Health Service (NHS).

In May 2024, a threat actor called “salfetka” claimed to sell the source code of INC Ransom’s Windows and Linux/ESXi encrypter versions for $300,000 on the Exploit and XSS hacking forums.

Microsoft revealed on Wednesday that its threat analysts have observed the financially motivated Vanilla Tempest threat actor using INC ransomware for the first time in an attack on the U.S. healthcare sector.

During the attack, Vanilla Tempest gained network access through the Storm-0494 threat actor, who infected the victim’s systems with the Gootloader malware downloader.

Once inside, the attackers backdoored the systems with Supper malware and deployed the legitimate AnyDesk remote monitoring and MEGA data synchronization tools.

The attackers then moved laterally using Remote Desktop Protocol (RDP) and the Windows Management Instrumentation Provider Host to deploy INC ransomware across the victim’s network.

While Microsoft didn’t name the victim hit by the Vanilla Tempest-orchestrated INC ransomware healthcare attack, the same ransomware strain was linked to a cyberattack against Michigan’s McLaren Health Care hospitals last month.

The attack disrupted IT and phone systems, caused the health system to lose access to patient information databases, and forced it to reschedule some appointments and non-emergent or elective procedures “out of an abundance of caution.”

Who is Vanilla Tempest?

Active since at least early June 2021, Vanilla Tempest (previously tracked as DEV-0832 and Vice Society) has frequently targeted sectors, including education, healthcare, IT, and manufacturing, using various ransomware strains such as BlackCat, Quantum Locker, Zeppelin, and Rhysida.

While active as Vice Society, the threat actor was known for using multiple ransomware strains during attacks, including Hello Kitty/Five Hands and Zeppelin ransomware.

CheckPoint linked Vice Society with the Rhysida ransomware gang in August 2023, another operation known for targeting healthcare, which tried to sell patient data stolen from Lurie Children’s Hospital in Chicago.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:42 am, Jun 24, 2025
weather icon 14°C
L: 14° | H: 15°
broken clouds
Humidity: 82 %
Pressure: 1013 mb
Wind: 12 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
14° | 15°°C 0 mm 0% 14 mph 82 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
17° | 25°°C 1 mm 100% 17 mph 91 % 1017 mb 0 mm/h
Fri Jun 27 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 16 mph 71 % 1020 mb 0 mm/h
Sat Jun 28 10:00 pm
weather icon
18° | 28°°C 0 mm 0% 12 mph 88 % 1023 mb 0 mm/h
Today 7:00 am
weather icon
14° | 15°°C 0 mm 0% 11 mph 82 % 1013 mb 0 mm/h
Today 10:00 am
weather icon
15° | 18°°C 0 mm 0% 13 mph 79 % 1013 mb 0 mm/h
Today 1:00 pm
weather icon
18° | 20°°C 0 mm 0% 14 mph 75 % 1012 mb 0 mm/h
Today 4:00 pm
weather icon
22° | 22°°C 0 mm 0% 13 mph 61 % 1012 mb 0 mm/h
Today 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 12 mph 52 % 1011 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 9 mph 67 % 1013 mb 0 mm/h
Tomorrow 1:00 am
weather icon
17° | 17°°C 0 mm 0% 8 mph 78 % 1013 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 6 mph 86 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€90,547.69
3.66%
Ethereum(ETH)
€2,069.71
7.21%
Tether(USDT)
€0.86
0.04%
XRP(XRP)
€1.85
6.43%
Solana(SOL)
€123.53
7.38%
USDC(USDC)
€0.86
0.02%
Dogecoin(DOGE)
€0.140655
6.74%
Shiba Inu(SHIB)
€0.000010
8.53%
Pepe(PEPE)
€0.000009
11.67%
Scroll to Top