Healthcare Breach Data Through Mid-2026: Declining Breach Counts, Sustained Ransomware Volume, and Expanding Insider Threat
Executive Summary
HHS OCR breach filings for healthcare are running 6.4% below the same period last year, with year-to-date victim counts down 22.1% from 2025 and 37.7% from 2024 [9]. That decline in formal breach reporting contrasts with Comparitech's tracking of 410 ransomware attacks against healthcare in H1 2026, a 14% increase over H2 2025, averaging 2.3 attacks per day [3]. The median breach size has dropped roughly 40% year-over-year to 2,451 individuals, reflecting a compositional shift toward smaller entities [8]. Meanwhile, the ITRC recorded 21 insider wrongdoing events in H1 2026, a sevenfold increase over all of 2025 [1]. Healthcare recorded 281 compromises in H1 2026, second only to financial services at 387 [1]. Only 24% of breach notices contained attack vector details, the lowest transparency rate the ITRC has ever recorded [1].
These numbers collectively describe a sector where large, headline-generating mega-breaches have temporarily migrated to other industries (no healthcare breach made the cross-sector top 10 in H1 2026 [2]), but the underlying attack tempo against healthcare providers and their supply chain has not abated.
HHS OCR Breach Filings: Volume Down, Hacking Dominant
Year-to-date figures through June 30, 2026 show healthcare data breaches down 3.2% from the corresponding period in 2024 and down 6.4% from 2025 [9]. Almost 34 million individuals had PHI exposed, stolen, or impermissibly disclosed in that window, a 37.7% reduction from 2024's high of 54.4 million and a 22.1% reduction from 2025 [9]. An HHS OCR-derived dashboard current through September 4, 2026 shows 506 large-breach filings and 74,872,402 individuals affected year-to-date [11].
June 2026 saw 66 large healthcare data breaches reported to OCR, a slight increase from 64 in May [9]. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per month; eight years ago, in 2018, the rate was roughly one per day [9]. Two or more large healthcare data breaches per day is the current baseline.
Medcurity's analysis of OCR portal data through June 5, 2026 found that 87% of reported H1 2026 healthcare breaches (246 of 283 submissions) were classified as Hacking/IT incidents [8]. Network servers were the breach site in 69% of recent breach reports and accounted for approximately 90% of all individuals affected in the trailing-quarter snapshot of the 100 most recent reports [8]. Physical-world breaches effectively vanished, accounting for two of 283 reports [8].
The full-year 2025 baseline showed 804 large healthcare breach filings submitted to OCR, affecting 140,574,754 individuals, with hacking/IT filings representing 651 of 804 (81%) [11]. The H1 2026 hacking share at 87% represents a further tightening of cause concentration.
Median Breach Size Collapse and Target Composition Shift
The median 2026 breach affected 2,451 individuals, down roughly 40% from H1 2025's median of 4,078 [8]. This does not indicate improved defenses across the sector. It reflects a shift in which organizations are being breached: the typical victim is now a specialty practice, community clinic, or small business associate rather than a large integrated health system [8].
June 2026's median breach size was 6,306 individuals, with an average of 68,181 [9]. The gap between mean and median confirms that a small number of large incidents still drive aggregate victim counts while the modal breach is shrinking.
H1 2026's largest named healthcare breaches include DentaQuest (15,000,000 individuals), Aesto (9,540,683), Lumexa Imaging (5,830,949), and AdaptHealth (4,115,802) [19]. Seven healthcare breaches required more than 1 million notices: TriZetto Provider Solutions (3,433,965), QualDerm Partners (3,117,874), Nacogdoches Memorial Hospital (2,507,073), Navia Benefit Solutions (2,151,330), Insightin Health (1,949,534), and New York City Health and Hospitals Corporation (1,800,000) [2].
In 2025, healthcare providers accounted for 57.5% of breaches, business associates for 35.8%, and health plans for 6.5% [10]. More than a third of breaches now originate with a vendor rather than the covered entity itself.
Ransomware: 410 Attacks in H1 2026
Comparitech recorded 410 ransomware attacks against the healthcare sector in H1 2026, a 14% increase from H2 2025 [3]. Of those, 247 targeted hospitals, clinics, and other healthcare providers while 163 affected healthcare businesses including pharmaceutical manufacturers, medical billing firms, and health technology companies [3]. Attacks against providers increased about 3% from the prior half, while attacks on healthcare businesses climbed nearly 35% [3].
Confirmed attacks (acknowledged by the affected organization or matching a publicly disclosed incident) numbered 55 against providers and 22 against healthcare businesses [3]. Those confirmed incidents exposed at least 424,740 patient records at providers and 154,825 records at healthcare businesses [3].
The United States recorded the highest number of healthcare ransomware attacks overall with 225 incidents, followed by Germany, India, Canada, and Australia [3].
Ransom Demand Escalation
The average ransom demand across confirmed healthcare incidents in Q1 2026 surged to $16.9 million, up from $577,800 in Q4 2025 [4] [5] [6]. The largest single demand reached $100 million, issued by the NetRunner group against Nippon Medical School Musashi Kosugi Hospital in Japan; the hospital did not pay [4] [5]. Median ransom demands were $310,000 for providers and $300,000 for healthcare businesses [3].
Ransomware groups claimed to have stolen more than twice as much data from healthcare businesses as from providers: 29 terabytes versus 13, despite providers facing higher attack volume [6].
Most Active Ransomware Groups
The most prolific ransomware gangs in Q1 2026 across all sectors were Qilin (353 attack claims), The Gentlemen (202), Akira (201), INC (131), Clop (122), and Play (119) [4]. By July 2026, The Gentlemen and Qilin together accounted for nearly 33% of all attacks, with The Gentlemen at 135 attacks and Qilin at 125 [7].
Qilin claimed 1,358 victims between April 2025 and March 2026, a 443% increase over the prior 12 months [27]. No arrest, indictment, sanction, or joint government advisory has targeted Qilin as of August 2026 [27]. The group focuses heavily on direct care providers, while INC concentrates more on healthcare businesses [6]. Recent Qilin healthcare victims include Imperial Healthcare Solutions (September 11, 2026) [16] [23], New World Diagnostics in the Philippines (September 28, 2026) [14] [30], and Arnold Center (September 28, 2026) [15].
The Gentlemen, a RaaS operation that emerged in mid-2025, has claimed over 400 victims across at least 70 countries [20]. An early May 2026 leak of the group's internal communications infrastructure (via a compromise of hosting provider 4VPS.SU) exposed 22 Rocket.Chat room exports spanning November 2025 through late April 2026, revealing tooling, victim targeting pipelines, negotiation tactics, and affiliate relationships [21].
Akira has impacted over 250 organizations since March 2023, with primary entry through unpatched VPN appliances (SonicWall CVE-2024-40766, Cisco CVE-2023-20269, CVE-2020-3259) and through stolen or brute-forced VPN credentials where MFA is absent [22] [26] [29].
Insider Wrongdoing Surge and DPRK IT Worker Infiltration
The ITRC tracked 21 insider wrongdoing events in H1 2026, a sevenfold increase over 2025's full-year total [1]. Cyberattacks accounted for 69.7% of data breaches in H1 2026 and 92.3% of all victim notices; system and human error accounted for 6.9% of breaches and 0.9% of victim notices [2].
DPRK IT worker schemes account for part of the insider surge, expanding beyond technology roles into healthcare and sales positions [12]. The campaign is tracked under monikers including Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta (formerly TAG-121), UNC5267, and Wagemole. It uses stolen or forged identity documents, VPNs, and proxy services to mask identity and location [12]. These schemes generate an estimated $800 million annually for the North Korean regime [13].
In February 2026, three employees of an Australian healthcare company were flagged as North Korean workers impersonating Chinese individuals after being found repeatedly connecting through Astrill VPN and IPRoyal Proxy, using fraudulently created identity documents [12]. Because DPRK workers obtain legitimate credentials and system access, they function as insider threats capable of data theft, installing backdoors for future cyberattacks, and extorting employers after termination [13].
Huntress noted the detection challenge: "DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations' environments, they're tricking companies into remotely hiring them" [12].
Breach Cost
Healthcare data breaches cost an average of $6.64 million in 2026, the costliest of any industry for a 13th consecutive year per IBM's Cost of a Data Breach Report [10]. That figure is roughly a third higher than the second-place sector (financial services at $6.29 million) and $1.65 million above the all-industry global average of $4.99 million [10]. The number represents a 10.5% year-over-year decline from $7.42 million in 2025 [10].
IOC Table
| Type | Value | Context | Source |
|---|---|---|---|
| malware | Qilin | Most prolific ransomware gang, 353 Q1 2026 claims; healthcare-focused | [4] |
| malware | The Gentlemen | 202 Q1 2026 claims; 135 claims in July 2026 alone | [4] [7] |
| malware | Akira | 201 Q1 2026 claims; entry via unpatched VPN | [4] |
| malware | INC | 131 Q1 2026 claims; concentrates on healthcare businesses | [4] [6] |
| malware | NetRunner | $100M demand against Nippon Medical School | [4] |
| malware | LockBit | Attacked Mt. Spokane Pediatrics, Elmwood Healthcare Jan 2026 | [5] |
| malware | DragonForce | Targeted Kopran Ltd Feb 2026; 284 GB exfiltrated | [5] |
| domain | nwdi.com.ph |
New World Diagnostics, Qilin victim Sep 28, 2026 | [14] |
| domain | arnoldcenter.org |
Arnold Center, Qilin victim Sep 28, 2026 | [15] |
| filename | README-GENTLEMEN.txt |
The Gentlemen ransom note | [20] |
| filename | README-RECOVER-[extension].txt |
Qilin ransom note per victim | [27] |
| filename | rwdrv.sys |
Qilin ransomware loader driver | [27] |
| filename | hlpdrv.sys |
Qilin driver killing security processes | [27] |
| filename | msimg32.dll |
Qilin multi-stage loader file | [27] |
| filename | akira_readme.txt |
Akira ransom note | [26] |
| filename | PSEXESVC.exe |
PsExec service binary used by Akira | [26] |
| filename | Win.exe |
Akira encryptor binary | [22] |
| filename | w.exe |
Akira encryptor binary | [22] |
| domain | ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
Qilin leak site | [23] |
MITRE ATT&CK Mapping
The following techniques are directly supported by source material on the ransomware groups active against healthcare in H1 2026:
| Technique | Name | Context | Source |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | Akira entry via VPN vulns (CVE-2024-40766, CVE-2023-20269, CVE-2020-3259); Qilin exploits internet-facing apps | [22] [26] [28] |
| T1078 | Valid Accounts | Akira and Qilin use stolen/brute-forced VPN credentials | [22] [27] [28] |
| T1133 | External Remote Services | VPN and RDP as primary entry; DPRK workers use VPN for remote access | [12] [22] [26] |
| T1566.001 | Phishing: Spearphishing Attachment | Qilin credential harvesting campaigns | [28] |
| T1003 | OS Credential Dumping | Akira extracts NTDS.dit offline from copied VMDK | [26] |
| T1003.001 | LSASS Memory | Akira dumps LSASS via comsvcs.dll | [26] |
| T1021.002 | SMB/Windows Admin Shares | Qilin and Akira lateral movement via PsExec | [26] [28] |
| T1059.001 | PowerShell | Akira shadow copy deletion, service disabling | [26] |
| T1486 | Data Encrypted for Impact | All listed groups perform encryption for ransom | [3] [4] |
| T1490 | Inhibit System Recovery | Shadow copy deletion by Akira and Qilin | [22] [26] |
| T1489 | Service Stop | Akira disables services pre-encryption | [26] |
| T1562.001 | Disable or Modify Tools | The Gentlemen custom defense evasion tools; Qilin driver-based security process termination | [20] [27] |
| T1070.001 | Clear Windows Event Logs | The Gentlemen clears Security, System, Application logs | [20] |
| T1567.002 | Exfiltration to Cloud Storage | Akira exfiltration via rclone to mega.nz; Qilin via easyupload.io | [25] [26] |
| T1219 | Remote Access Software | Akira installs AnyDesk, LogMeIn, MobaXterm for persistence | [26] |
| T1136.002 | Create Account: Domain Account | Akira creates accounts (e.g., "itadm") for persistence | [26] |
| T1068 | Exploitation for Privilege Escalation | Akira exploits Veeam CVE-2024-40711 | [26] |
VPN Authentication Anomalies
Akira and Qilin intrusions frequently begin with valid credentials obtained from criminal channels, used an average of 6.1 days before ransomware execution [27]. Hunt for:
- New geographic origins or ASNs in VPN authentication logs
- Successful VPN logins from accounts that have not been used in 90+ days
- Multiple failed VPN authentications followed by a success from a different source IP
- VPN appliance firmware versions against CISA KEV entries for CVE-2024-40766, CVE-2023-20269, CVE-2020-3259
Ransomware Staging Indicators
title: Qilin or Akira Ransomware Staging Artifacts
status: experimental
author: RedSheepSec
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|endswith:
- '\rwdrv.sys'
- '\hlpdrv.sys'
- '\msimg32.dll'
- '\Win.exe'
- '\w.exe'
- '\PSEXESVC.exe'
- '\spawningcmd.exe'
- '\orpowershell.exe'
condition: selection
level: high
The Gentlemen Defense Evasion
Monitor for bulk event log clearing. The Gentlemen affiliates clear Security, System, and Application Event Logs while leaving other Windows Event Logs untouched [20]. Event ID 1102 (Security log cleared) and 104 (System log cleared) in close temporal proximity are strong indicators.
DPRK Insider Detection
Look for remote employees connecting through Astrill VPN or IPRoyal Proxy services [12]. Cross-reference onboarding documentation for anomalies in submitted identity documents, particularly passport photographs with similarities across multiple employees and word anomalies in electronic bills submitted as proof of residence [12].
Exfiltration Indicators
Ransomware groups claimed 29 TB exfiltrated from healthcare businesses and 13 TB from providers in Q1 2026 alone [6]. Monitor for:
- Large outbound transfers to
mega.nzoreasyupload.io[25] [26] - Rclone process execution or command-line arguments containing cloud storage provider names
- WinRAR or 7-Zip archiving of sensitive directories prior to transfer
Analysis
The H1 2026 data presents three concurrent dynamics that require separate analytical frameworks.
First, the formal breach reporting decline (6.4% YoY per OCR [9]) and the absence of healthcare breaches from the cross-sector top 10 [2] do not represent reduced threat activity. They reflect a temporary shift in mega-breach concentration to other sectors. The Instructure Holdings Canvas breach alone (275 million notices) and Under Armour (72.7 million) dominated cross-sector totals [1] [2]. Healthcare's operational breach tempo, measured by Comparitech's ransomware tracking, actually increased.
Second, the target composition shift toward smaller entities is significant. The 40% decline in median breach size [8] combined with a sustained breach count means attacker economics have changed. Qilin, the most active healthcare-targeting group, operates on a RaaS model with affiliates likely seeking higher success rates against under-resourced targets rather than attempting complex intrusions against large health systems with mature security programs.
Third, the insider wrongdoing surge (21 events in H1 2026 vs. approximately 3 in all of 2025 [1]) and DPRK worker infiltration into healthcare roles [12] represent a qualitatively different threat vector that traditional perimeter security controls do not address. These actors obtain legitimate credentials and perform actual work, making behavioral detection the primary available countermeasure.
Verizon's 2026 DBIR dataset includes 1,492 healthcare incidents and 1,438 confirmed healthcare breaches [11], a substantially larger corpus than OCR's 506 YTD filings [11], suggesting significant underreporting or differences in incident classification thresholds.
Red Sheep Assessment
Confidence: Moderate
The data collectively suggests that healthcare ransomware activity has reached a self-sustaining operational tempo that is unlikely to decline absent significant law enforcement disruption of the top groups. Qilin's 443% year-over-year growth in victim claims [27], combined with the absence of any arrest, indictment, or sanction against the group [27], creates an enforcement vacuum that affiliates will continue to exploit.
The 35% increase in attacks on healthcare businesses versus 3% on direct providers [3] points to a deliberate strategic shift. Healthcare business associates and supply chain entities often hold aggregated data from multiple covered entities but operate with fewer security resources. A single compromise of a pharmacy benefit manager, billing company, or practice management software vendor can yield data volumes comparable to a large health system breach. The MedImpact breach (Qilin, October 2025 intrusion, notifications not sent until September 2026) and the Polish Medyc practice-management software compromise (access from mid-2024 until August 2026, potentially affecting five million patients) both illustrate this pattern [18] [17].
The transparency crisis is worth tracking. Only 24% of H1 2026 breach notices contained attack vector details [1]. This makes defender-to-defender intelligence sharing through ISACs and direct peer relationships more important than relying on public breach notifications for tactical intelligence.
An alternative interpretation: the decline in formal breach counts and victim totals could indicate that large health system defenses are genuinely improving after years of investment, and that the increased attack volume against smaller entities represents attackers being pushed downmarket. Both interpretations can be true simultaneously.
Defender's Checklist
- ▢[ ] Audit all VPN appliance firmware versions against CISA KEV entries for CVE-2024-40766 (SonicWall), CVE-2023-20269, and CVE-2020-3259 (Cisco), and enforce MFA on all VPN accounts. Qilin intrusions average 6.1 days dwell time from initial access to execution [27].
- ▢[ ] Review third-party and business associate access. More than a third of 2025 healthcare breaches originated with a vendor [10]. Validate that business associates have current SOC 2 reports and confirm MFA enforcement on all remote access to your environment.
- ▢[ ] Implement detection for bulk Windows Event Log clearing (Event IDs 1102, 104) and monitor for
rwdrv.sys,hlpdrv.sys, andPSEXESVC.exefile creation events on endpoints, using the Sigma rule above or equivalent EDR queries.
- ▢[ ] Evaluate remote workforce onboarding controls against DPRK insider indicators: Astrill VPN or IPRoyal Proxy connections, identity document anomalies across multiple employees, and electronic bill inconsistencies [12]. Coordinate HR, legal, IT, and security teams on a cross-functional screening process [13].
- ▢[ ] Monitor outbound data transfers to
mega.nzandeasyupload.iovia DNS logs, proxy logs, or DLP tooling. Ransomware groups exfiltrated 42 TB from healthcare targets in Q1 2026 alone [6].
References
- ITRC: Malicious Insiders Surge as H1 2026 Data Compromises Set Pace for Record Year
- Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches
- Healthcare ransomware attacks rose 14% in first half of 2026, report finds
- Ransomware roundup: Q1 2026 - Comparitech
- Comparitech assesses healthcare ransomware decline in volume but escalates in impact
- Average ransom demands surge for healthcare ransomware attacks in 2026
- Ransomware roundup: July 2026 - Comparitech
- HIPAA Enforcement & Breach Trends Through Mid-2026: A Medcurity Analysis
- June 2026 Healthcare Data Breach Report
- Healthcare Data Breach Statistics 2026: Cost & HIPAA
- Healthcare Data Breach Statistics 2026: 506 YTD Breaches
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
- Hidden in Plain Sight: Labor, Employment and Cybersecurity Risks of DPRK IT Worker Infiltration
- Qilin Ransomware Attack on New World Diagnostics
- Qilin Ransomware Targets Arnold Center
- Ransomware Group qilin Hits: Imperial Healthcare Solutions
- eHealth Cyber Brief, 28 Sep 2026
- Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems
- DC Medicaid Breach Exposes 399,086 Records
- The Gentleman Ransomware Defense Evasion TTPs Uncovered, Huntress
- The Gentlemen Ransomware Group Leak Analysis
- IC3 #StopRansomware: Akira Ransomware Advisory
- Ransom! Imperial Healthcare Solutions (SEP-2026)
- Qilin Targets XICO in Ransomware Attack
- Qilin: Top Ransomware Threat to SLTTs in Q2 2025
- Akira Ransomware: IOCs, MITRE TTPs & Detection
- Qilin Ransomware Explained: Attack Chain, Victims, and Defenses
- QILIN Ransomware: 15+ Victims in 48-Hour Blitz
- Akira Ransomware: Attack Chain, Victims, and 2026 Status
- Ransom! New World Diagnostics (SEP-2026)
Event Timeline
Timeline
Entity Relationships
Entity Graph (17 entities, 41 relationships)
Diamond Model
Diamond Model
Hunt Guide: Healthcare Ransomware Ecosystem, Qilin, Akira, The Gentlemen, and DPRK Insider Threat Activity Through Mid-2026
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If Qilin, Akira, The Gentlemen, or DPRK insider threat operators are active in our environment, we expect to observe VPN authentication anomalies from previously unseen geolocations or dormant accounts, file creation events for known ransomware staging artifacts (rwdrv.sys, hlpdrv.sys, PSEXESVC.exe, Win.exe, w.exe), bulk Windows Event Log clearing (Event IDs 1102 and 104), lateral movement via PsExec or WMI, credential dumping from LSASS or NTDS.dit, outbound data transfers to mega.nz or easyupload.io, and remote access connections through Astrill VPN or IPRoyal Proxy services in Sysmon, Windows Security, PowerShell, DNS, firewall, and VPN authentication logs.
Intelligence Summary: Comparitech tracked 410 ransomware attacks against healthcare in H1 2026, a 14% increase over H2 2025, with Qilin, The Gentlemen, and Akira as the most prolific groups. Qilin claimed 1,358 victims between April 2025 and March 2026, a 443% year-over-year increase, with no law enforcement action taken against the group as of August 2026. Separately, the ITRC recorded a sevenfold increase in insider wrongdoing events in H1 2026, with DPRK IT worker infiltration schemes expanding into healthcare roles using stolen identity documents, Astrill VPN, and IPRoyal Proxy to mask their origin.
Confidence: Moderate | Priority: Critical
Scope
- Networks: All healthcare network segments including clinical systems, EHR infrastructure, medical device networks, VPN concentrators, business associate remote access points, and cloud-hosted healthcare applications. Prioritize DMZ-facing VPN appliances (SonicWall, Cisco ASA/FTD), Veeam Backup infrastructure, and Active Directory domain controllers.
- Timeframe: Retrospective 30-day lookback from hunt initiation, with emphasis on the trailing 7 days for active compromise indicators. Qilin intrusions average 6.1 days dwell time from initial access to execution, so a 14-day sliding window captures the full pre-encryption phase.
- Priority Systems: VPN concentrators (SonicWall SMA, Cisco ASA/FTD/AnyConnect), Active Directory domain controllers, Veeam Backup and Replication servers, file servers containing PHI, EHR application servers, pharmacy benefit management systems, medical billing platforms, and any systems with business associate remote access.
MITRE ATT&CK Techniques
T1190: Exploit Public-Facing Application (Initial Access) [P1]
Akira gains initial access by exploiting unpatched VPN appliances, specifically SonicWall CVE-2024-40766 and Cisco CVE-2023-20269 and CVE-2020-3259. Qilin also exploits internet-facing applications as a primary entry vector.
Splunk SPL:
index=firewall-pan sourcetype="pan:threat" (severity="critical" OR severity="high") (cve="CVE-2024-40766" OR cve="CVE-2023-20269" OR cve="CVE-2020-3259" OR cve="CVE-2024-40711")
| stats count by src_ip dest_ip dest_port cve action
| sort -count
Elastic KQL:
event.dataset:"panw.threat" AND (vulnerability.id:"CVE-2024-40766" OR vulnerability.id:"CVE-2023-20269" OR vulnerability.id:"CVE-2020-3259" OR vulnerability.id:"CVE-2024-40711") AND event.severity:("critical" OR "high")
Sigma Rule:
title: VPN Appliance Exploitation Attempt for Known Akira Entry CVEs
id: a1b2c3d4-5678-9012-abcd-ef0123456789
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects exploitation attempts against VPN appliance CVEs used by Akira and Qilin ransomware groups for initial access.
logsource:
category: firewall
product: paloalto
detection:
selection:
cve|contains:
- 'CVE-2024-40766'
- 'CVE-2023-20269'
- 'CVE-2020-3259'
- 'CVE-2024-40711'
condition: selection
level: critical
tags:
- attack.initial_access
- attack.t1190
Requires firewall or IDS/IPS signatures that tag CVE IDs. If your VPN appliance logs do not contain CVE identifiers, correlate with CISA KEV list and patch status from vulnerability scanning data. False positives may include vulnerability scanners; filter by known scanner source IPs.
T1078: Valid Accounts (Initial Access) [P2]
Both Akira and Qilin use stolen or brute-forced VPN credentials as a primary initial access method. Qilin intrusions average 6.1 days dwell time from credential use to ransomware execution. DPRK IT workers also obtain legitimate credentials through fraudulent hiring.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4624 Logon_Type=10
| stats count dc(src_ip) as unique_sources values(src_ip) as source_ips by Account_Name
| where unique_sources > 3
| sort -unique_sources
| table Account_Name unique_sources source_ips count
Elastic KQL:
event.code:"4624" AND winlog.event_data.LogonType:"10" | stats unique_count(source.ip) by user.name
Sigma Rule:
title: VPN Login from Dormant Account
id: b2c3d4e5-6789-0123-bcde-f01234567890
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects successful authentication from accounts that have not been active in 90+ days, a pattern observed in Akira and Qilin initial access via stolen credentials.
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
LogonType:
- 3
- 10
condition: selection
level: medium
tags:
- attack.initial_access
- attack.t1078
This Sigma rule is a baseline; effective hunting requires correlating against a known-active accounts baseline to identify dormant account usage. In Splunk, join with asset/identity data to identify accounts not seen in 90+ days. Expect false positives from service accounts and seasonal users.
T1133: External Remote Services (Initial Access) [P2]
VPN and RDP serve as primary entry points for Akira and Qilin. DPRK IT workers use Astrill VPN and IPRoyal Proxy to mask their true location while maintaining remote access to employer systems.
Splunk SPL:
index=corelight sourcetype=corelight_conn dest_port IN (443, 1194, 1723, 4500, 500, 3389)
| iplocation id.orig_h
| stats count dc(id.resp_h) as targets values(id.resp_h) as target_list by id.orig_h Country
| where count > 50 OR targets > 5
| sort -count
| table id.orig_h Country targets target_list count
Elastic KQL:
destination.port:(443 OR 1194 OR 1723 OR 4500 OR 500 OR 3389) AND event.dataset:"corelight.conn" AND NOT source.geo.country_iso_code:"US"
Sigma Rule:
title: DPRK Worker Proxy Service VPN Connection
id: c3d4e5f6-7890-1234-cdef-012345678901
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects connections associated with Astrill VPN or IPRoyal Proxy, services observed in DPRK IT worker infiltration schemes targeting healthcare organizations.
logsource:
category: proxy
detection:
selection_dns:
c-uri|contains:
- 'astrill'
- 'iproyal'
condition: selection_dns
level: high
tags:
- attack.initial_access
- attack.t1133
Astrill VPN and IPRoyal Proxy may be used by legitimate users in some environments. Correlate with HR onboarding records and identity verification data. Detection is most useful when combined with identity document anomaly review.
T1566.001: Phishing: Spearphishing Attachment (Initial Access) [P2]
Qilin uses credential harvesting campaigns via spearphishing attachments as one vector for obtaining valid credentials used in subsequent intrusions.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=11
| where match(TargetFilename, "(?i)\\(Users|Temp|Downloads)\\.*\.(hta|iso|img|vhd|lnk|chm|js|vbs|wsf)$")
| stats count by Computer user TargetFilename
| sort -count
Elastic KQL:
event.code:"11" AND file.path:(*\\Users\\*\\Downloads\\* OR *\\Temp\\*) AND file.extension:("hta" OR "iso" OR "img" OR "vhd" OR "lnk" OR "chm" OR "js" OR "vbs" OR "wsf")
Qilin phishing campaigns are credential-focused; monitor for subsequent VPN authentication from harvested accounts rather than expecting traditional payload delivery.
T1003.001: LSASS Memory (Credential Access) [P1]
Akira dumps LSASS via comsvcs.dll and extracts NTDS.dit offline from copied VMDK files. Also uses Creds.ps1 and Ladon.exe for credential harvesting.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 AND (CommandLine="*comsvcs*" AND CommandLine="*MiniDump*") OR (CommandLine="*Creds.ps1*") OR (CommandLine="*Ladon.exe*") OR (Image="*\\procdump*" AND CommandLine="*lsass*"))
| stats count by Computer user Image CommandLine
| sort -count
Elastic KQL:
(event.code:"1" AND process.command_line:(*comsvcs* AND *MiniDump*)) OR (event.code:"1" AND process.command_line:(*Creds.ps1* OR *Ladon.exe*)) OR (event.code:"10" AND winlog.event_data.TargetImage:*lsass.exe*)
Sigma Rule:
title: LSASS Credential Dumping via comsvcs.dll - Akira TTP
id: d4e5f607-8901-2345-def0-123456789012
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects LSASS memory dumping via comsvcs.dll MiniDump, a technique used by Akira ransomware operators.
references:
- https://www.manageengine.com/malware-protection/adversaries/akira-ransomware.html
logsource:
category: process_creation
product: windows
detection:
selection_comsvcs:
CommandLine|contains|all:
- 'comsvcs'
- 'MiniDump'
selection_tools:
CommandLine|contains:
- 'Creds.ps1'
- 'Ladon.exe'
condition: selection_comsvcs or selection_tools
level: critical
tags:
- attack.credential_access
- attack.t1003.001
comsvcs.dll MiniDump is rarely used legitimately. Ladon.exe is a penetration testing tool that should not be present in healthcare environments. Creds.ps1 is an Akira-specific artifact.
T1021.002: SMB/Windows Admin Shares (Lateral Movement) [P1]
Both Qilin and Akira use PsExec for lateral movement via SMB admin shares. Qilin also uses wmiexec.py and wmic.exe.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(Image, "(?i)(PSEXESVC\.exe|psexec\.exe|psexec64\.exe|wmiexec|spawningcmd\.exe|orpowershell\.exe)")
| stats count values(CommandLine) as commands by Computer user Image ParentImage
| sort -count
Elastic KQL:
event.code:"1" AND process.name:("PSEXESVC.exe" OR "psexec.exe" OR "psexec64.exe" OR "spawningcmd.exe" OR "orpowershell.exe" OR "wmic.exe" OR "wmi.exe")
Sigma Rule:
title: Qilin and Akira Lateral Movement Tools
id: e5f60718-9012-3456-ef01-234567890123
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects execution of lateral movement tools associated with Qilin and Akira ransomware, including PsExec, spawningcmd.exe, orpowershell.exe, and WMI-based tools.
references:
- https://securityarsenal.com/blog/qilin-ransomware-15-victims-in-48-hour-blitz-us-healthcar
- https://www.manageengine.com/malware-protection/adversaries/akira-ransomware.html
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\PSEXESVC.exe'
- '\psexec.exe'
- '\psexec64.exe'
- '\spawningcmd.exe'
- '\orpowershell.exe'
- '\wmiexec.py'
condition: selection
level: high
tags:
- attack.lateral_movement
- attack.t1021.002
PsExec is sometimes used for legitimate administration; correlate with change management records. spawningcmd.exe and orpowershell.exe are Qilin-specific artifacts with no legitimate use.
T1059.001: PowerShell (Execution) [P2]
Akira uses PowerShell for shadow copy deletion and service disabling pre-encryption. PowerShell is also used for credential harvesting scripts (Creds.ps1).
Splunk SPL:
index=powershell sourcetype=XmlWinEventLog EventCode=4104
| where match(ScriptBlockText, "(?i)(vssadmin.*delete|wmic.*shadowcopy|Creds\.ps1|Stop-Service|Disable-Service|Get-WmiObject.*Win32_ShadowCopy)")
| stats count by Computer UserID ScriptBlockText
| sort -count
Elastic KQL:
event.code:"4104" AND powershell.script_block_text:(*vssadmin* AND *delete*) OR (*shadowcopy*) OR (*Creds.ps1*) OR (*Stop-Service*)
Sigma Rule:
title: Akira Ransomware PowerShell Pre-Encryption Activity
id: f6071829-0123-4567-f012-345678901234
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects PowerShell commands used by Akira ransomware for shadow copy deletion and service disabling prior to encryption.
references:
- https://www.manageengine.com/malware-protection/adversaries/akira-ransomware.html
logsource:
product: windows
category: ps_script
detection:
selection_shadow:
ScriptBlockText|contains:
- 'vssadmin delete shadows'
- 'Win32_ShadowCopy'
- 'wmic shadowcopy delete'
selection_service:
ScriptBlockText|contains:
- 'Stop-Service'
- 'Set-Service'
condition: selection_shadow or selection_service
level: high
tags:
- attack.execution
- attack.t1059.001
Shadow copy deletion via PowerShell is a high-fidelity indicator when not associated with known backup or patching workflows. Stop-Service may generate false positives from legitimate administration; correlate with time-of-day and user context.
T1486: Data Encrypted for Impact (Impact) [P1]
All listed ransomware groups (Qilin, Akira, The Gentlemen, INC, LockBit, DragonForce, NetRunner) encrypt victim data for ransom. Akira uses Win.exe and w.exe as encryptor binaries. Qilin drops README-RECOVER ransom notes.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=11
| where match(TargetFilename, "(?i)(README-GENTLEMEN\.txt|akira_readme\.txt|README-RECOVER|fn\.txt|akiranew\.txt)")
| stats count by Computer user TargetFilename
| sort -count
Elastic KQL:
event.code:"11" AND file.name:("README-GENTLEMEN.txt" OR "akira_readme.txt" OR "README-RECOVER*" OR "fn.txt" OR "akiranew.txt")
Sigma Rule:
title: Ransomware Ransom Note Creation - Qilin, Akira, The Gentlemen
id: 07182930-1234-5678-0123-456789012345
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects creation of ransom note files associated with Qilin (README-RECOVER), Akira (akira_readme.txt, fn.txt, akiranew.txt), and The Gentlemen (README-GENTLEMEN.txt) ransomware families.
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|endswith:
- '\README-GENTLEMEN.txt'
- '\akira_readme.txt'
- '\fn.txt'
- '\akiranew.txt'
selection_qilin:
TargetFilename|contains:
- 'README-RECOVER'
condition: selection or selection_qilin
level: critical
tags:
- attack.impact
- attack.t1486
Ransom note creation is a late-stage indicator. This detection serves as confirmation of active encryption rather than a preventive measure. Trigger immediate IR escalation.
T1490: Inhibit System Recovery (Impact) [P1]
Akira and Qilin delete shadow copies before encryption using vssadmin.exe and wmic.exe to prevent recovery.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(CommandLine, "(?i)(vssadmin.*delete.*shadows|wmic.*shadowcopy.*delete|bcdedit.*recoveryenabled.*no)")
| stats count by Computer user Image CommandLine ParentImage
| sort -count
Elastic KQL:
event.code:"1" AND process.command_line:(*vssadmin* AND *delete* AND *shadows*) OR (*wmic* AND *shadowcopy* AND *delete*) OR (*bcdedit* AND *recoveryenabled* AND *no*)
Shadow copy deletion outside of known backup windows is almost always malicious. Combine with T1486 detections for correlation.
T1562.001: Disable or Modify Tools (Defense Evasion) [P1]
The Gentlemen use custom defense evasion tools. Qilin deploys rwdrv.sys and hlpdrv.sys kernel drivers to terminate security processes. These drivers are loaded to bypass endpoint protection prior to encryption.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog (EventCode=6 AND (ImageLoaded="*\\rwdrv.sys" OR ImageLoaded="*\\hlpdrv.sys" OR ImageLoaded="*\\ThrottleStop.sys")) OR (EventCode=11 AND (TargetFilename="*\\rwdrv.sys" OR TargetFilename="*\\hlpdrv.sys" OR TargetFilename="*\\ThrottleStop.sys"))
| stats count by Computer EventCode Image ImageLoaded TargetFilename
| sort -count
Elastic KQL:
(event.code:"6" AND driver.name:("rwdrv.sys" OR "hlpdrv.sys" OR "ThrottleStop.sys")) OR (event.code:"11" AND file.name:("rwdrv.sys" OR "hlpdrv.sys" OR "ThrottleStop.sys"))
Sigma Rule:
title: Qilin Ransomware Malicious Driver Loading
id: 18293041-2345-6789-1234-567890123456
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects loading or creation of rwdrv.sys, hlpdrv.sys, or ThrottleStop.sys, drivers used by Qilin ransomware to terminate security processes before encryption.
references:
- https://www.adaptivesecurity.com/blog/qilin-ransomware
logsource:
category: driver_load
product: windows
detection:
selection:
ImageLoaded|endswith:
- '\rwdrv.sys'
- '\hlpdrv.sys'
- '\ThrottleStop.sys'
condition: selection
level: critical
tags:
- attack.defense_evasion
- attack.t1562.001
ThrottleStop.sys is a renamed legitimate driver repurposed by Qilin. rwdrv.sys and hlpdrv.sys have no legitimate use in healthcare environments. Any detection should trigger immediate containment.
T1070.001: Clear Windows Event Logs (Defense Evasion) [P1]
The Gentlemen affiliates clear Security, System, and Application Event Logs while leaving other logs untouched. Event IDs 1102 (Security log cleared) and 104 (System log cleared) in close temporal proximity are strong indicators.
Splunk SPL:
index=winevent sourcetype=XmlWinEventLog (EventCode=1102 OR EventCode=104)
| bin _time span=5m
| stats count dc(EventCode) as unique_events values(EventCode) as cleared_logs by _time Computer SubjectUserName
| where unique_events >= 2
| sort -_time
Elastic KQL:
event.code:("1102" OR "104") | stats unique_count(event.code) by host.name, @timestamp
Sigma Rule:
title: Bulk Windows Event Log Clearing - The Gentlemen TTP
id: 29304152-3456-7890-2345-678901234567
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects clearing of multiple Windows Event Logs (Security, System, Application) in short succession, a technique observed in The Gentlemen ransomware operations.
references:
- https://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps
logsource:
product: windows
service: security
detection:
selection_security:
EventID: 1102
condition: selection_security
level: high
tags:
- attack.defense_evasion
- attack.t1070.001
Legitimate log clearing does occur during maintenance windows. Correlate with change management tickets. Two or more distinct log channels cleared within five minutes outside a maintenance window is a high-fidelity indicator.
T1567.002: Exfiltration to Cloud Storage (Exfiltration) [P1]
Akira exfiltrates data via rclone to mega.nz. Qilin exfiltrates via WinRAR to easyupload.io. Ransomware groups claimed 42 TB exfiltrated from healthcare targets in Q1 2026.
Splunk SPL:
index=corelight sourcetype=corelight_dns
| where match(query, "(?i)(mega\.nz|easyupload\.io)")
| stats count by id.orig_h query answers
| sort -count
Elastic KQL:
dns.question.name:(*mega.nz* OR *easyupload.io*)
Sigma Rule:
title: DNS Query to Ransomware Exfiltration Destinations
id: 30415263-4567-8901-3456-789012345678
status: experimental
author: RedSheepSec
date: 2026/10/07
description: Detects DNS queries to mega.nz and easyupload.io, cloud storage services used by Akira and Qilin ransomware for data exfiltration.
references:
- https://www.cisecurity.org/insights/blog/qilin-top-ransomware-threat-to-sltts-in-q2-2025
- https://www.manageengine.com/malware-protection/adversaries/akira-ransomware.html
logsource:
category: dns
detection:
selection:
query|endswith:
- '.mega.nz'
- '.mega.co.nz'
- '.easyupload.io'
condition: selection
level: high
tags:
- attack.exfiltration
- attack.t1567.002
mega.nz is a legitimate file sharing service; correlate with volume of data transferred and user context. easyupload.io has less legitimate enterprise use and is a higher-confidence indicator. Also monitor for rclone.exe process execution.
T1219: Remote Access Software (Command and Control) [P2]
Akira installs AnyDesk, LogMeIn, MobaXterm, and Level.io RMM tools for persistence and command-and-control after initial compromise.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(Image, "(?i)(AnyDesk|LogMeIn|MobaXterm|level\.io)")
| stats count by Computer user Image CommandLine ParentImage
| sort -count
Elastic KQL:
event.code:"1" AND process.name:(*AnyDesk* OR *LogMeIn* OR *MobaXterm*)
Some of these RMM tools may be legitimately provisioned by IT. Cross-reference with approved software inventory. Any installation not matching IT-provisioned tools should be investigated.
T1136.002: Create Account: Domain Account (Persistence) [P2]
Akira creates domain accounts such as 'itadm' for persistence after initial compromise.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4720
| stats count by TargetUserName SubjectUserName Computer
| sort -count
| table TargetUserName SubjectUserName Computer count
Elastic KQL:
event.code:"4720" AND winlog.event_data.TargetUserName:*
New domain account creation outside of provisioning workflows is suspicious. Look for accounts with names resembling IT admin roles (itadm, sysadm, etc.) created by non-standard processes.
T1489: Service Stop (Impact) [P2]
Akira disables services pre-encryption to prevent backup, AV, and database processes from interfering with encryption.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(CommandLine, "(?i)(net\s+stop|sc\s+stop|sc\s+config.*disabled)")
| bin _time span=5m
| stats count dc(CommandLine) as unique_stops by _time Computer user
| where unique_stops > 5
| sort -_time
Elastic KQL:
event.code:"1" AND process.command_line:(*"net stop"* OR *"sc stop"* OR *"sc config"* AND *disabled*)
Bulk service stopping (more than 5 services in 5 minutes) outside maintenance windows is a strong pre-encryption indicator.
T1068: Exploitation for Privilege Escalation (Privilege Escalation) [P1]
Akira exploits Veeam Backup and Replication CVE-2024-40711 for privilege escalation. Veeam.Backup.MountService.exe and VeeamHax.exe are associated artifacts.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(Image, "(?i)(VeeamHax\.exe|Veeam\.Backup\.MountService\.exe)") OR match(CommandLine, "(?i)VeeamHax")
| stats count by Computer user Image CommandLine ParentImage
| sort -count
Elastic KQL:
event.code:"1" AND (process.name:("VeeamHax.exe" OR "Veeam.Backup.MountService.exe") OR process.command_line:*VeeamHax*)
VeeamHax.exe is a known exploit tool; any detection is a confirmed malicious indicator. Patch Veeam Backup and Replication against CVE-2024-40711.
Indicators of Compromise
| Type | Value | Context | |
|---|---|---|---|
| ip | 193.233.202.17 |
The Gentlemen ransomware C2 IP used via svchost.exe proxy \ | AbuseIPDB confidence 0% (0 reports, US) |
| ip | 77.110.122.137 |
The Gentlemen ransomware C2 IP used for scheduled task persistence \ | AbuseIPDB confidence 0% (0 reports, US) |
| ip | 91.245.35.22 |
The Gentlemen leak infrastructure SOCKS5 proxy IP identified from leaked internal communications \ | AbuseIPDB confidence 0% (0 reports, RU) |
| hash_sha256 | 0b5b31af5956158bfbd14f6cbf4f1bca23c5d16a40dbf3758f3289146c565f43 |
Akira ransomware Windows sample (VirusTotal 63/74 malicious) \ | VirusTotal 63/74 malicious (ransomware.akira/smyxdjjt) |
| hash_sha256 | 0d700ca5f6cc093de4abba9410480ee7a8870d5e8fe86c9ce103eec3872f225f |
Akira ransomware Windows sample (VirusTotal 63/75 malicious) \ | VirusTotal 63/75 malicious (ransomware.akira/encoder) |
| hash_sha256 | a2df5477cf924bd41241a3326060cc2f913aff2379858b148ddec455e4da67bc |
Akira ransomware Windows sample (VirusTotal 61/75 malicious) \ | VirusTotal 61/75 malicious (ransomware.akira/smyxdjjt) |
| hash_sha256 | 03aa12ac2884251aa24bf0ccd854047de403591a8537e6aba19e822807e06a45 |
Akira ransomware Windows sample (VirusTotal 64/75 malicious) \ | VirusTotal 64/75 malicious (ransomware.akira/smyxdjjt) |
| hash_sha256 | 2e88e55cc8ee364bf90e7a51671366efb3dac3e9468005b044164ba0f1624422 |
Akira ransomware Windows sample (VirusTotal 57/75 malicious) \ | VirusTotal 57/75 malicious (ransomware.akira/encoder) |
| hash_sha256 | 40221e1c2e0c09bc6104548ee847b6ec790413d6ece06ad675fff87e5b8dc1d5 |
Akira ransomware Windows sample (VirusTotal 63/75 malicious) \ | VirusTotal 63/75 malicious (ransomware.akira/smyxdjjt) |
| hash_sha256 | 5ea65e2bb9d245913ad69ce90e3bd9647eb16d992301145372565486c77568a2 |
Akira ransomware Windows sample (VirusTotal 63/74 malicious) \ | VirusTotal 63/74 malicious (ransomware.akira/smyxdjjt) |
| hash_sha256 | 643061ac0b51f8c77f2ed202dc91afb9879f796ddd974489209d45f84f644562 |
Akira ransomware Windows sample (VirusTotal 55/74 malicious) \ | VirusTotal 55/74 malicious (ransomware.akira/smyxdjjt) |
| hash_sha256 | 6f9d50bab16b2532f4683eeb76bd25449d83bdd6c85bf0b05f716a4b49584f84 |
Akira ransomware Windows sample (VirusTotal 62/75 malicious) \ | VirusTotal 62/75 malicious (ransomware.akira/smyxdjjt) |
| hash_sha256 | fef09b0aa37cbdb6a8f60a6bd8b473a7e5bffdc7fd2e952444f781574abccf64 |
Akira ransomware Windows sample (VirusTotal 62/74 malicious) \ | VirusTotal 62/74 malicious (ransomware.akira/smyxdjjt) |
| hash_sha256 | e1321a4b2b104f31aceaf4b19c5559e40ba35b73a754d3ae13d8e90c53146c0f |
Akira ransomware Linux/ELF sample (VirusTotal 36/75 malicious) \ | VirusTotal 36/75 malicious (ransomware.akira/smyxdfw) |
| hash_sha256 | 74f497088b49b745e6377b32ed5d9dfaef3c84c7c0bb50fabf30363ad2e0bfb1 |
Akira ransomware Linux/ELF sample (VirusTotal 25/75 malicious) \ | VirusTotal 25/75 malicious (ransomware.akira/ransm) |
| hash_sha256 | 3d2b58ef6df743ce58669d7387ff94740ceb0122c4fc1c4ffd81af00e72e60a4 |
Akira ransomware Linux/ELF sample (VirusTotal 36/74 malicious) \ | VirusTotal 36/74 malicious (ransomware.akira/r002c0de324) |
| domain | nwdi.com.ph |
New World Diagnostics domain, Qilin ransomware victim September 28, 2026 \ | VirusTotal 0/91 malicious |
| domain | arnoldcenter.org |
Arnold Center domain, Qilin ransomware victim September 28, 2026 \ | VirusTotal 0/91 malicious |
| domain | ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion |
Qilin ransomware leak site used for victim data publication \ | VirusTotal 15/91 malicious |
| domain | level.io |
RMM tool domain used by Akira threat actors for persistence per IC3 advisory \ | VirusTotal 0/91 malicious |
| domain | xicoled.com |
Qilin ransomware victim domain, Xico \ | VirusTotal 0/91 malicious |
| domain | easyupload.io |
Qilin exfiltration destination used with WinRAR for data staging \ | VirusTotal 0/91 malicious |
| domain | mega.nz |
Akira ransomware exfiltration destination via rclone \ | VirusTotal 1/91 malicious |
| filename | README-GENTLEMEN.txt |
The Gentlemen ransomware ransom note filename | |
| filename | Win.exe |
Akira ransomware encryptor binary | |
| filename | w.exe |
Akira ransomware encryptor binary | |
| filename | locker.exe |
Akira ransomware malicious artifact per IC3 advisory | |
| filename | rwdrv.sys |
Qilin ransomware loader driver used to bypass endpoint protection | |
| filename | hlpdrv.sys |
Qilin driver used to kill security processes before encryption | |
| filename | msimg32.dll |
Qilin multi-stage loader file used in DLL side-loading chain | |
| filename | ThrottleStop.sys |
Renamed driver used in Qilin ransomware driver-loading chain | |
| filename | PSEXESVC.exe |
PsExec service binary used by both Akira and Qilin for lateral movement | |
| filename | akira_readme.txt |
Akira ransomware ransom note filename | |
| filename | spawningcmd.exe |
Qilin ransomware service execution artifact | |
| filename | orpowershell.exe |
Qilin ransomware service execution artifact | |
| filename | netscan.exe |
SoftPerfect network scanning tool used by Akira for discovery | |
| filename | VeeamHax.exe |
Akira Megazord exploit tool targeting Veeam CVE-2024-40711 | |
| filename | Creds.ps1 |
Akira credential harvesting PowerShell script | |
| filename | Ladon.exe |
Akira Kerberos ticket dumping tool | |
| filename | qKtul.vbs |
Akira ransomware associated VBScript file | |
| filename | wmiexec.py |
Akira lateral movement tool leveraging WMI | |
| filename | fn.txt |
Akira ransomware ransom note filename | |
| filename | akiranew.txt |
Akira ransomware ESXi ransom note filename | |
| filename | Veeam.Backup.MountService.exe |
Akira privilege escalation via Veeam service exploitation | |
| filename | comsvcs.dll |
Used by Akira for LSASS credential dumping via MiniDump technique | |
| filename | Vssadmin.exe |
Used by Akira actors for shadow copy deletion per IC3 advisory | |
| filename | psexec.exe |
Qilin lateral movement tool | |
| filename | psexec64.exe |
Qilin lateral movement tool, 64-bit variant | |
| filename | mstsc.exe |
Qilin RDP activation detection artifact | |
| registry | HKLM\SYSTEM\ControlSet001\Services\msiserver |
The Gentlemen actor registry key artifact for persistence or evasion | |
| url | http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=c696224e-7b55-42fd-975d-523482859420 |
Qilin leak site victim post for Imperial Healthcare Solutions | |
| url | http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=477fec77-060d-441e-bff3-641490e9923c |
Qilin leak site victim post for New World Diagnostics |
IOC Sweep Queries (Splunk):
index=corelight sourcetype=corelight_conn (id.orig_h="193.233.202.17" OR id.resp_h="193.233.202.17")
| stats count min(_time) as first_seen max(_time) as last_seen by id.orig_h id.resp_h id.resp_p proto
| eval first_seen=strftime(first_seen,"%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen,"%Y-%m-%d %H:%M:%S")
| sort -count
index=corelight sourcetype=corelight_conn (id.orig_h="77.110.122.137" OR id.resp_h="77.110.122.137")
| stats count min(_time) as first_seen max(_time) as last_seen by id.orig_h id.resp_h id.resp_p proto
| eval first_seen=strftime(first_seen,"%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen,"%Y-%m-%d %H:%M:%S")
| sort -count
index=corelight sourcetype=corelight_conn (id.orig_h="91.245.35.22" OR id.resp_h="91.245.35.22")
| stats count min(_time) as first_seen max(_time) as last_seen by id.orig_h id.resp_h id.resp_p proto
| eval first_seen=strftime(first_seen,"%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen,"%Y-%m-%d %H:%M:%S")
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*0b5b31af5956158bfbd14f6cbf4f1bca23c5d16a40dbf3758f3289146c565f43*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*0d700ca5f6cc093de4abba9410480ee7a8870d5e8fe86c9ce103eec3872f225f*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*a2df5477cf924bd41241a3326060cc2f913aff2379858b148ddec455e4da67bc*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*03aa12ac2884251aa24bf0ccd854047de403591a8537e6aba19e822807e06a45*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*2e88e55cc8ee364bf90e7a51671366efb3dac3e9468005b044164ba0f1624422*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*40221e1c2e0c09bc6104548ee847b6ec790413d6ece06ad675fff87e5b8dc1d5*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*5ea65e2bb9d245913ad69ce90e3bd9647eb16d992301145372565486c77568a2*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*643061ac0b51f8c77f2ed202dc91afb9879f796ddd974489209d45f84f644562*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*6f9d50bab16b2532f4683eeb76bd25449d83bdd6c85bf0b05f716a4b49584f84*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog Hashes="*fef09b0aa37cbdb6a8f60a6bd8b473a7e5bffdc7fd2e952444f781574abccf64*"
| stats count by Computer Image TargetFilename CommandLine
| sort -count
index=crowdstrike sourcetype="CrowdStrike:Event:Streams:JSON" SHA256HashData="e1321a4b2b104f31aceaf4b19c5559e40ba35b73a754d3ae13d8e90c53146c0f"
| stats count by aid ComputerName FileName CommandLine
| sort -count
index=crowdstrike sourcetype="CrowdStrike:Event:Streams:JSON" SHA256HashData="74f497088b49b745e6377b32ed5d9dfaef3c84c7c0bb50fabf30363ad2e0bfb1"
| stats count by aid ComputerName FileName CommandLine
| sort -count
index=crowdstrike sourcetype="CrowdStrike:Event:Streams:JSON" SHA256HashData="3d2b58ef6df743ce58669d7387ff94740ceb0122c4fc1c4ffd81af00e72e60a4"
| stats count by aid ComputerName FileName CommandLine
| sort -count
index=corelight sourcetype=corelight_dns query="*nwdi.com.ph*"
| stats count by id.orig_h query answers
| sort -count
index=corelight sourcetype=corelight_dns query="*arnoldcenter.org*"
| stats count by id.orig_h query answers
| sort -count
index=corelight sourcetype=corelight_dns query="*ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd*"
| stats count by id.orig_h query answers
| sort -count
index=corelight sourcetype=corelight_dns query="*level.io*"
| stats count by id.orig_h query answers
| sort -count
index=corelight sourcetype=corelight_dns query="*xicoled.com*"
| stats count by id.orig_h query answers
| sort -count
index=corelight sourcetype=corelight_dns query="*easyupload.io*"
| stats count by id.orig_h query answers
| sort -count
index=corelight sourcetype=corelight_dns query="*mega.nz*"
| stats count by id.orig_h query answers
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=11 TargetFilename="*README-GENTLEMEN.txt*"
| stats count by Computer user TargetFilename
| sort -count
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 AND Image="*\\Win.exe") OR (EventCode=11 AND TargetFilename="*\\Win.exe")
| stats count by Computer user Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 AND Image="*\\w.exe") OR (EventCode=11 AND TargetFilename="*\\w.exe")
| stats count by Computer user Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 AND Image="*\\locker.exe") OR (EventCode=11 AND TargetFilename="*\\locker.exe")
| stats count by Computer user Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog (EventCode=6 AND ImageLoaded="*\\rwdrv.sys") OR (EventCode=11 AND TargetFilename="*\\rwdrv.sys")
| stats count by Computer Image ImageLoaded TargetFilename
| sort -count
index=sysmon sourcetype=XmlWinEventLog (EventCode=6 AND ImageLoaded="*\\hlpdrv.sys") OR (EventCode=11 AND TargetFilename="*\\hlpdrv.sys")
| stats count by Computer Image ImageLoaded TargetFilename
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=7 ImageLoaded="*\\msimg32.dll"
| where NOT match(ImageLoaded, "(?i)Windows\\System32|Windows\\SysWOW64")
| stats count by Computer Image ImageLoaded
| sort -count
index=sysmon sourcetype=XmlWinEventLog (EventCode=6 AND ImageLoaded="*\\ThrottleStop.sys") OR (EventCode=11 AND TargetFilename="*\\ThrottleStop.sys")
| stats count by Computer Image ImageLoaded TargetFilename
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\PSEXESVC.exe"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=11 TargetFilename="*akira_readme.txt*"
| stats count by Computer user TargetFilename
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\spawningcmd.exe"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\orpowershell.exe"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\netscan.exe"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 AND Image="*\\VeeamHax.exe") OR (EventCode=11 AND TargetFilename="*\\VeeamHax.exe")
| stats count by Computer user Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*Creds.ps1*"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\Ladon.exe"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog (EventCode=1 AND CommandLine="*qKtul.vbs*") OR (EventCode=11 AND TargetFilename="*qKtul.vbs*")
| stats count by Computer user Image TargetFilename CommandLine
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*wmiexec*"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=11 TargetFilename="*\\fn.txt"
| stats count by Computer user TargetFilename
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=11 TargetFilename="*akiranew.txt*"
| stats count by Computer user TargetFilename
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\Veeam.Backup.MountService.exe" ParentImage!="*\\Veeam*"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 CommandLine="*comsvcs*MiniDump*"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\Vssadmin.exe" CommandLine="*delete*shadow*"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\psexec.exe"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\psexec64.exe"
| stats count by Computer user Image CommandLine ParentImage
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=1 Image="*\\mstsc.exe"
| stats count by Computer user CommandLine ParentImage
| where ParentImage!="*explorer.exe"
| sort -count
index=sysmon sourcetype=XmlWinEventLog EventCode=13 TargetObject="*ControlSet001\\Services\\msiserver*"
| stats count by Computer user Image TargetObject Details
| sort -count
index=corelight sourcetype=corelight_http uri="*ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd*"
| stats count by id.orig_h host uri
| sort -count
index=corelight sourcetype=corelight_http uri="*ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd*"
| stats count by id.orig_h host uri
| sort -count
YARA Rules
akira_ransomware_windows: Detects Akira ransomware Windows samples based on verified SHA256 hashes from IC3 advisory and associated file artifacts
rule akira_ransomware_windows {
meta:
description = "Detects Akira ransomware Windows samples based on IC3 advisory hashes and artifacts"
author = "RedSheepSec"
date = "2026-10-07"
reference = "https://www.ic3.gov/CSA/2025/251113.pdf"
threat = "Akira Ransomware"
strings:
$note1 = "akira_readme.txt" ascii wide
$note2 = "akiranew.txt" ascii wide
$note3 = "fn.txt" ascii wide
$tool1 = "VeeamHax" ascii wide
$tool2 = "Creds.ps1" ascii wide
$tool3 = "locker.exe" ascii wide
$ext = ".akira" ascii wide
condition:
uint16(0) == 0x5A4D and (any of ($note*) or any of ($tool*) or $ext)
}
qilin_ransomware_artifacts: Detects Qilin ransomware staging artifacts including driver files and loader components
rule qilin_ransomware_artifacts {
meta:
description = "Detects Qilin ransomware staging artifacts - drivers and loader components"
author = "RedSheepSec"
date = "2026-10-07"
reference = "https://www.adaptivesecurity.com/blog/qilin-ransomware"
threat = "Qilin Ransomware"
strings:
$driver1 = "rwdrv.sys" ascii wide
$driver2 = "hlpdrv.sys" ascii wide
$loader = "msimg32.dll" ascii wide
$note = "README-RECOVER" ascii wide
$svc1 = "spawningcmd.exe" ascii wide
$svc2 = "orpowershell.exe" ascii wide
condition:
2 of them
}
gentlemen_ransomware_note: Detects The Gentlemen ransomware ransom note and associated artifacts
rule gentlemen_ransomware_note {
meta:
description = "Detects The Gentlemen ransomware ransom note"
author = "RedSheepSec"
date = "2026-10-07"
reference = "https://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps"
threat = "The Gentlemen Ransomware"
strings:
$note = "README-GENTLEMEN.txt" ascii wide nocase
$marker = "GENTLEMEN" ascii wide
condition:
all of them
}
Suricata Rules
SID 9000001: Detects DNS query to easyupload.io, a data exfiltration destination used by Qilin ransomware
alert dns $HOME_NET any -> any 53 (msg:"HUNT Qilin Exfil - DNS Query to easyupload.io"; dns.query; content:"easyupload.io"; nocase; classtype:policy-violation; sid:9000001; rev:1; metadata:created_at 2026_10_07;)
SID 9000002: Detects DNS query to mega.nz, an exfiltration destination used by Akira ransomware via rclone
alert dns $HOME_NET any -> any 53 (msg:"HUNT Akira Exfil - DNS Query to mega.nz"; dns.query; content:"mega.nz"; nocase; classtype:policy-violation; sid:9000002; rev:1; metadata:created_at 2026_10_07;)
SID 9000003: Detects outbound connection to The Gentlemen ransomware C2 IP 193.233.202.17
alert ip $HOME_NET any -> 193.233.202.17 any (msg:"HUNT The Gentlemen C2 - 193.233.202.17"; classtype:trojan-activity; sid:9000003; rev:1; metadata:created_at 2026_10_07;)
SID 9000004: Detects outbound connection to The Gentlemen ransomware C2 IP 77.110.122.137
alert ip $HOME_NET any -> 77.110.122.137 any (msg:"HUNT The Gentlemen C2 - 77.110.122.137"; classtype:trojan-activity; sid:9000004; rev:1; metadata:created_at 2026_10_07;)
SID 9000005: Detects outbound connection to The Gentlemen leak infrastructure SOCKS5 proxy 91.245.35.22
alert ip $HOME_NET any -> 91.245.35.22 any (msg:"HUNT The Gentlemen Infrastructure - 91.245.35.22"; classtype:trojan-activity; sid:9000005; rev:1; metadata:created_at 2026_10_07;)
SID 9000006: Detects DNS query to level.io RMM tool domain used by Akira for persistence
alert dns $HOME_NET any -> any 53 (msg:"HUNT Akira RMM - DNS Query to level.io"; dns.query; content:"level.io"; nocase; classtype:policy-violation; sid:9000006; rev:1; metadata:created_at 2026_10_07;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Sysmon (EventID 1, 6, 7, 10, 11, 13) | T1190, T1078, T1003.001, T1021.002, T1059.001, T1486, T1490, T1489, T1562.001, T1219, T1136.002, T1068 | Sysmon must be deployed with a configuration that logs process creation (1), driver loads (6), image loads (7), process access (10), file creation (11), and registry events (13). index=sysmon in this environment. |
| Windows Security Event Log (EventID 1102, 4624, 4625, 4720) | T1078, T1070.001, T1136.002 | Windows Security event forwarding to index=winevent. Ensure Event IDs 1102 (log cleared), 4624/4625 (logon success/failure), and 4720 (account creation) are being collected. |
| Windows System Event Log (EventID 104, 7036) | T1070.001, T1489 | System log clearing (104) and service state changes (7036) should be forwarded to index=winevent. |
| PowerShell ScriptBlock Logging (EventID 4104) | T1059.001, T1003.001 | Requires PowerShell ScriptBlock Logging enabled via GPO. Logs to index=powershell in this environment. |
| Corelight/Zeek DNS, HTTP, Conn, SSL | T1567.002, T1133, T1190 | Network metadata from Corelight sensors in index=corelight. Required for exfiltration domain detection (mega.nz, easyupload.io), VPN connection analysis, and network anomaly detection. |
| Palo Alto Firewall (pan:threat, pan:traffic) | T1190, T1133 | Perimeter firewall logs in index=firewall-pan. CVE-based threat signatures require up-to-date PAN content updates. |
| CrowdStrike EDR | T1486, T1562.001, T1003.001 | EDR telemetry in index=crowdstrike provides hash-based detection, behavioral analysis, and process genealogy. Required for Linux/ELF Akira sample detection. |
| VPN Authentication Logs | T1078, T1133 | VPN authentication logs may reside in firewall logs, RADIUS/TACACS logs, or vendor-specific sources. Verify forwarding covers both successful and failed authentication events with source IP and geolocation data. |
| DNS Server Logs | T1567.002 | DNS resolution logs in index=dns or index=corelight (corelight_dns). Critical for detecting queries to exfiltration and C2 domains. |
Mitigations & Recommendations
Curated baseline: LockBit; library archetype
Established mitigations (curated):
- Execute all steps from Ransomware archetype containment (network isolation, backup protection, krbtgt reset, etc.).
- Block CISA-published LockBit C2 and exfil IPs/domains at perimeter.
- If Citrix ADC is deployed and Citrix Bleed is the vector: invalidate ALL ADC sessions and rotate session keys.
- Block MegaSync / rclone / StealBit process execution via EDR or AppLocker policy.
- Hunt peers of patient zero for LockBit precursor (commodity loader like Qakbot, IcedID, Bumblebee).
Established detection guidance (curated):
- Confirm LockBit by matching ransom note filename, wallpaper text, or encrypted file extension against CISA / vendor IOC list.
- Determine affiliate initial access vector: exploited edge CVE, phished credentials, brute-forced RDP, or IAB handoff.
- Scan for StealBit exfil tool and rclone misuse.
- Check for shadow copy deletion and recovery-disabling commands (shared with all ransomware but especially consistent for LockBit).
- Citrix Bleed session hijack hunt (if Citrix ADC/NetScaler is deployed).
- LockBit-specific service termination list: identify stopped services that LockBit kills pre-encryption.
Net-new from this incident:
- Patch all SonicWall SMA appliances against CVE-2024-40766 and all Cisco ASA/FTD appliances against CVE-2023-20269 and CVE-2020-3259 immediately. Enforce MFA on all VPN accounts without exception; Akira and Qilin specifically target environments where MFA is absent.
- Patch Veeam Backup and Replication against CVE-2024-40711. Restrict network access to Veeam management interfaces to authorized administrator workstations only.
- Deploy all Sigma rules from this hunt report across Sysmon and Windows Security event sources. Prioritize the Qilin driver loading rule (rwdrv.sys, hlpdrv.sys) and The Gentlemen log clearing rule (Event IDs 1102, 104) as these target pre-encryption activity with the highest response value.
- Deploy Suricata rules SID 9000001 through 9000006 on network sensors monitoring egress traffic to detect exfiltration to easyupload.io and mega.nz, C2 communications to The Gentlemen infrastructure IPs, and Level.io RMM tool usage.
- Ingest all 15 Akira SHA256 hashes and 3 The Gentlemen C2 IPs into CrowdStrike custom IOC lists and Splunk lookup tables for continuous matching against endpoint and network telemetry.
- Block unauthorized RMM tools (AnyDesk, LogMeIn, MobaXterm, Level.io) via application control policies. If any of these are IT-provisioned, create allow-list exceptions and alert on usage outside provisioned deployments.
- Coordinate with HR and security teams to implement DPRK insider threat screening controls: flag Astrill VPN and IPRoyal Proxy connections from remote employees, review identity verification documents for cross-employee similarities, and audit electronic bills submitted as proof of residence for formatting anomalies.
- Review all business associate remote access connections. Over one-third of 2025 healthcare breaches originated with a vendor. Validate current SOC 2 reports, confirm MFA enforcement on vendor access, and establish monitoring for vendor credential misuse.
- Monitor outbound data volumes by host across all egress paths. Qilin and Akira collectively exfiltrated 42 TB from healthcare targets in Q1 2026 alone. Set alerting thresholds for outbound transfers exceeding baseline by 200% to any single destination.
Sources
- ITRC: Malicious Insiders Surge as H1 2026 Data Compromises Set Pace for Record Year
- Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches
- Healthcare ransomware attacks rose 14% in first half of 2026, report finds
- Ransomware roundup: Q1 2026 - Comparitech
- Comparitech assesses healthcare ransomware decline in volume but escalates in impact
- Average ransom demands surge for healthcare ransomware attacks in 2026
- Ransomware roundup: July 2026 - Comparitech
- HIPAA Enforcement and Breach Trends Through Mid-2026: A Medcurity Analysis
- June 2026 Healthcare Data Breach Report
- Healthcare Data Breach Statistics 2026: Cost and HIPAA
- Healthcare Data Breach Statistics 2026: 506 YTD Breaches
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
- Hidden in Plain Sight: Labor, Employment and Cybersecurity Risks of DPRK IT Worker Infiltration
- Qilin Ransomware Attack on New World Diagnostics
- Qilin Ransomware Targets Arnold Center
- Ransomware Group qilin Hits: Imperial Healthcare Solutions
- eHealth Cyber Brief, 28 Sep 2026
- Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems
- DC Medicaid Breach Exposes 399,086 Records
- The Gentleman Ransomware Defense Evasion TTPs Uncovered, Huntress
- The Gentlemen Ransomware Group Leak Analysis
- IC3 StopRansomware: Akira Ransomware Advisory
- Ransom! Imperial Healthcare Solutions (SEP-2026)
- Qilin Targets XICO in Ransomware Attack
- Qilin: Top Ransomware Threat to SLTTs in Q2 2025
- Akira Ransomware: IOCs, MITRE TTPs and Detection
- Qilin Ransomware Explained: Attack Chain, Victims, and Defenses
- QILIN Ransomware: 15+ Victims in 48-Hour Blitz
- Akira Ransomware: Attack Chain, Victims, and 2026 Status
- Ransom! New World Diagnostics (SEP-2026)