Microsoft warns US healthcare of threat actor using new ransomware
Vanilla Tempest, a ransomware group also known as Vice Society, has been seen deploying the INC ransomware strain for the first time to target the American healthcare sector.
This is according to cybersecurity researchers from Microsoft, who recently detailed their newest findings in an X thread.
In the thread, the company said Vanilla Tempest first receives hands-off from Gootloader infections by Storm-0494, before deploying different malware and software, including Supper, AnyDesk, MEGA, and others.
Vice Society
The group uses Remote Desktop Protocol (RDP) for lateral movement, and Windows Management Instrumentation Provider Host to deploy the INC ransomware.
Unfortunately, Microsoft did not say which organizations Vanilla Tempest targeted, or how successful it was. Ransomware attacks against healthcare firms usually result in the leak of highly sensitive medical data, as well as potentially dizzying payouts.
Vanilla Tempest, or Vice Society, is a threat actor that’s been active since mid-2022. It usually targets education, healthcare, IT, and manufacturing sectors, and is known for frequently switching between different encryptors. While affiliates usually stick to one or two encryptors, Vanilla Tempest was observed using BlackCat, Quantum Locker, Zeppelin, Rhysida, and others.
In October 2022, Microsoft warned about Vanilla Tempest, saying it was known for swapping ransomware payloads as it targeted schools in the US. In some cases, Microsoft added, the group skips the encryption part altogether and just steals the data.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Some of its victims include the Swedish furniture powerhouse IKEA, as well as the Los Angeles Unified School District (LAUSD). IKEA fell prey in late November 2022, when its shops in Morocco and Kuwait were forced to shut parts of their infrastructure down. A few months earlier, LAUSD tried to negotiate with the group to keep the stolen sensitive data private, but the negotiations broke down.
“Unfortunately, as expected, data was recently released by a criminal organization,” LAUSD said soon after. “In partnership with law enforcement, our experts are analyzing the full extent of this data release.”
The identity of the hackers is unknown to this day.
Via The Hacker News
More from TechRadar Pro
Vanilla Tempest, a ransomware group also known as Vice Society, has been seen deploying the INC ransomware strain for the first time to target the American healthcare sector. This is according to cybersecurity researchers from Microsoft, who recently detailed their newest findings in an X thread. In the thread, the…
Recent Posts
- Amazon’s new plan for games: James Bond and AI Snoop Dogg
- How to watch France vs Ivory Coast: FREE streams, TV channels for World Cup 2026 warm-up
- Marshall Milton ANC review: Making the rare case for premium on-ear headphones
- Belkin’s new Joy-Con grips also boost the Switch 2’s battery life
- How to watch Spain vs Iraq: Free Streams & TV Channels for World Cup 2026 warm-up match
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023