Healthcare organizations averaged 102,209 malware hits per firewall during the first half of 2026, roughly four times the volume recorded by the next most targeted industry [1]. That figure comes from SonicWall's State of Healthcare Cybersecurity report. Alongside the raw volume, the sector posted an 83% attack retention rate, reportedly the highest of any tracked vertical [1]. Attacks don't spike and recede. They accumulate.
The more operationally significant finding sits underneath the volume numbers: 100% of the vulnerabilities exploited against healthcare organizations in the period analyzed by Securin (January 2025 through February 2026) were already cataloged in CISA's Known Exploited Vulnerabilities (KEV) list [5]. Attackers are not burning zero-days on hospitals. They are walking through doors that have been publicly documented, sometimes for years.
The KEV Problem Is the Defining Structural Failure
Securin's healthcare cyber threat intelligence report analyzed 592 incidents across 94 ransomware groups between January 2025 and February 2026 [5]. Approximately 59% of those incidents involved ransomware. A healthcare organization was hit roughly every 10 hours. Every single vulnerability chain used in those attacks had a corresponding KEV entry.
This means defenders had prior, public warning for every exploited flaw. The issue isn't a lack of intelligence. It's the gap between awareness and remediation.
Healthcare environments run complex networks of clinical systems, medical devices, and legacy platforms that can't be patched on standard enterprise cycles. Firmware updates on infusion pumps or imaging systems require vendor coordination, downtime scheduling, and clinical risk assessment. Attackers understand that gap and operate inside it.
SonicWall's data makes the consequences concrete. Legacy vulnerabilities like CVE-2021-36260, a command injection flaw in Hikvision cameras first disclosed in 2021, remain actively exploited against healthcare networks [1]. That CVE has been public for five years. It has been in the KEV catalog for most of that time. It is still being used to gain initial access.
Remote access infrastructure is another persistent target shaped by unpatched KEV entries. SonicWall detected 13.3 million UltraVNC exploitation attempts across the healthcare sector in the first five months of 2026 [1]. UltraVNC buffer overflow vulnerabilities are well documented. The volume of exploitation attempts indicates widespread exposure across healthcare environments that depend on remote access for clinical workflows and vendor support.
The Change Healthcare Breach Illustrates Systemic Weakness
The Change Healthcare ransomware attack in 2024 remains the most consequential example of what happens when known security gaps go unaddressed in a systemically important healthcare entity. That single incident disrupted claims processing nationwide, compromised the medical data of approximately 190 million individuals, and resulted in a $22 million ransom payment [3]. The attack path relied on compromised credentials used to access a Citrix remote access portal that lacked multifactor authentication.
Change Healthcare processed approximately 15 billion healthcare transactions annually before the breach [3]. When it went down, providers across the country lost the ability to submit claims, verify insurance eligibility, and process prescriptions. The financial impact extended well beyond the ransom payment itself.
This incident demonstrated that a single vendor compromise can cascade across the entire sector. Available reporting indicates that over 80% of stolen protected health information records now originate from third-party vendors rather than the breached organizations themselves [3]. Supply chain compromise has become the dominant vector for large-scale healthcare data exposure.
Attack Volume Refuses to Decline at Industry Pace
Healthcare recorded the smallest attack decline of any tracked vertical. While intrusion prevention system (IPS) attack volumes dropped across most industries, healthcare saw only a 16.9% decrease [1]. SonicWall recorded 16.6 million ransomware detections across 10 active ransomware families targeting the sector [1].
The retention rate tells the story. At 83%, healthcare's attack retention rate means the vast majority of threat activity persists from one measurement period to the next [1]. Other industries see sharper drops as attackers shift focus. Healthcare doesn't get that relief because its structural conditions (legacy devices, complex vendor relationships, and regulatory constraints on downtime) remain constant.
Exploitation spanned 243 unique attack signatures targeting healthcare IoT devices [1]. Connected medical devices represent a particularly difficult remediation challenge. Many run embedded operating systems that can't be patched without the device manufacturer's involvement. Some devices are no longer supported by their manufacturers at all.
Clinical Outcomes Are Directly Affected
A joint study by Proofpoint and the Ponemon Institute found that nearly all healthcare entities experienced at least one cyberattack in the past year, with an average of more than 40 incidents per organization [4]. Nearly three in four U.S. healthcare organizations reported that those attacks disrupted patient care [4]. About half reported increased medical procedure complications and longer patient stays. Approximately one in four to one in three respondents linked cyber incidents to higher patient mortality rates [4].
These are clinical outcomes, not IT metrics. When a ransomware attack takes down an electronic health record system or disables imaging equipment, the downstream effect is measured in treatment delays, diagnostic errors, and patient diversions to other facilities.
The sector's sustained exposure is the product of specific structural conditions that multiple threat groups have learned to exploit systematically.
Regulatory Pressure Is Increasing
Clearwater Security leadership has described the current risk environment as defined by compounding, interconnected failure rather than isolated incidents [3]. That framing fits the data. Third-party incidents now routinely impact dozens or hundreds of organizations simultaneously.
The Senate Health, Education, Labor, and Pensions (HELP) Committee has been considering legislation aimed at strengthening cybersecurity requirements for healthcare entities, including mandatory incident reporting timelines and minimum security standards for business associates handling protected health information [3]. The regulatory direction is toward treating cybersecurity as a patient safety issue rather than a compliance checkbox.
Analysis
The KEV finding from Securin's data is the most actionable signal in the current threat picture. It means that prioritizing KEV remediation, specifically for internet-facing and remote access systems, would have addressed every vulnerability chain used in the 592 incidents recorded during the study period. This is a direct mapping between a specific defensive action and the actual attack surface being exploited.
The persistence of CVE-2021-36260 and UltraVNC exploitation at the volumes reported by SonicWall strongly suggests that healthcare organizations likely have incomplete asset inventories, particularly for IoT and remote access infrastructure. You can't patch what you don't know you have.
The 83% retention rate suggests that attackers view healthcare as a reliable, repeatable target. The combination of high-value data, payment willingness (due to clinical urgency), and slow remediation cycles makes the sector attractive to both financially motivated groups and initial access brokers who sell footholds to ransomware operators.
Red Sheep Assessment
Confidence: High
The convergence of SonicWall's volume data and Securin's KEV analysis points to a straightforward conclusion: the healthcare sector's security deficit is concentrated in known vulnerability management, not in defending against novel threats. Every exploited vulnerability in the Securin study period had a public advisory and a KEV listing. The problem is execution speed, not intelligence availability.
The 13.3 million UltraVNC exploitation attempts and the continued exploitation of a five-year-old Hikvision CVE suggest that many healthcare organizations lack continuous asset discovery and vulnerability scanning for non-traditional IT assets (cameras, remote access servers, IoT devices). Traditional vulnerability management programs focused on servers and workstations miss these categories entirely.
The third-party concentration of data breaches (reporting indicates over 80% of stolen records originating from vendors) suggests that even organizations with strong internal programs face substantial residual risk from their supply chains. The regulatory push toward minimum standards for business associates is a direct response to this gap, but implementation timelines will likely lag the threat.
A contrarian reading holds that the 16.9% decline in IPS attack volumes could signal the beginning of a plateau. The retention rate data does not support that interpretation. The decline is the smallest of any sector, and the retention rate indicates the underlying threat activity is persistent, not receding.
Defender's Checklist
- ▢[ ] Audit all internet-facing assets against the current CISA KEV catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog). Prioritize CVE-2021-36260 (Hikvision command injection), UltraVNC buffer overflow CVEs, remote access tools (VNC variants, RDP gateways), and IoT devices for immediate remediation or compensating controls. Align remediation timelines with CISA BOD 22-01 per-CVE deadlines.
- ▢[ ] Conduct an asset discovery sweep specifically targeting network-connected medical devices, cameras, and remote access infrastructure. Cross-reference results against your existing CMDB to identify unmanaged or unknown devices. Tools like Runzero, Claroty, or Medigate can assist with healthcare IoT discovery.
- ▢[ ] Review all business associate agreements for cybersecurity requirements. Verify that third-party vendors handling PHI meet minimum patching SLAs and can demonstrate KEV remediation within CISA-mandated timelines.
- ▢[ ] Deploy network segmentation between clinical device VLANs and general enterprise networks. Block outbound internet access from medical device segments except through explicit allow-list proxies. Monitor east-west traffic from IoT segments for anomalous connections.
- ▢[ ] Establish a recurring KEV review cadence (weekly at minimum) mapped to your vulnerability management program. Track mean-time-to-remediate for KEV entries separately from general vulnerability SLAs and report it to leadership as a patient safety metric.
References
- https://www.esecurityplanet.com/threats/healthcare-cybersecurity-threats-persist-in-2026/
- https://www.e-channelnews.com/sonicwall-research-sounds-code-red-on-healthcare-cybersecurity-as-attack-rates-refuse-to-decline/
- https://www.clearwatersecurity.com/healthcare-cybersecurity-outlook-2026/
- https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-and-ponemon-institute-report-reveals-impact-cyberattacks-patient
- https://www.securin.io/healthcare-sector-cyber-threat-intelligence-report-q1-2026
Entity Relationships
Entity Graph (3 entities, 1 relationships)
Diamond Model
Diamond Model
Hunt Guide: Healthcare Sector KEV Exploitation and Persistent Ransomware Targeting
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If threat actors are exploiting known vulnerabilities cataloged in CISA KEV (specifically CVE-2021-36260 in Hikvision devices and UltraVNC buffer overflow flaws) and leveraging unprotected remote access infrastructure to gain initial access for ransomware deployment in our healthcare environment, we expect to observe exploitation attempts against IoT/camera devices, high-volume VNC traffic anomalies, unauthorized remote access sessions lacking MFA, and ransomware precursor behaviors in firewall logs, network metadata, endpoint telemetry, and authentication logs.
Intelligence Summary: Healthcare organizations averaged 102,209 malware hits per firewall in H1 2026, roughly four times the next most targeted industry, with an 83% attack retention rate. Securin's analysis of 592 incidents across 94 ransomware groups (January 2025 through February 2026) found that 100% of exploited vulnerabilities were already cataloged in CISA's Known Exploited Vulnerabilities list, including the continued exploitation of CVE-2021-36260 (a five-year-old Hikvision command injection flaw) and 13.3 million UltraVNC exploitation attempts. The Change Healthcare ransomware attack demonstrated systemic risk from compromised credentials used against remote access portals lacking multifactor authentication, with reporting indicating over 80% of stolen PHI records originating from third-party vendors.
Confidence: High | Priority: Critical
Scope
- Networks: All internet-facing network segments, DMZ, remote access infrastructure (VPN concentrators, Citrix gateways, RDP gateways), medical device VLANs, IoT camera networks, and clinical workstation segments. Priority on segments hosting Hikvision cameras, VNC-accessible endpoints, and Citrix/remote access portals.
- Timeframe: Rolling 90-day hunt window, with initial focus on the last 30 days. Continuous monitoring recommended given the 83% attack retention rate indicating persistent threat activity against healthcare.
- Priority Systems: Citrix/VPN remote access gateways, UltraVNC/VNC servers, Hikvision IP cameras and NVRs, medical device management servers, EHR application servers, claims processing systems, and any business associate VPN connections. Focus on internet-facing assets with CISA KEV vulnerabilities.
MITRE ATT&CK Techniques
T1190: Exploit Public-Facing Application (Initial Access) [P1]
Attackers exploit known vulnerabilities in internet-facing healthcare systems, including Hikvision cameras (CVE-2021-36260 command injection), UltraVNC servers with buffer overflow flaws, and Citrix remote access portals. All exploited vulnerabilities in the Securin study period were already in the CISA KEV catalog, indicating threat actors deliberately target unpatched, publicly documented flaws in healthcare infrastructure.
Splunk SPL:
index=firewall-pan sourcetype="pan:threat" (severity="critical" OR severity="high") (cve="CVE-2021-36260" OR app="hikvision" OR app="ultravnc" OR app="vnc" OR app="citrix-ica")
| stats count by src_ip, dest_ip, dest_port, app, cve, severity, action
| where count > 5
| sort -count
| table src_ip, dest_ip, dest_port, app, cve, severity, action, count
Elastic KQL:
event.dataset:"panw.threat" AND (vulnerability.id:"CVE-2021-36260" OR network.application:("hikvision" OR "ultravnc" OR "vnc" OR "citrix")) AND event.severity:("critical" OR "high")
Sigma Rule:
title: Exploitation Attempt Against Healthcare IoT or Remote Access - KEV CVEs
id: a1b2c3d4-5678-90ab-cdef-1234567890ab
status: experimental
author: RedSheepSec
date: 2026/07/10
description: Detects potential exploitation attempts targeting Hikvision cameras (CVE-2021-36260), UltraVNC, or Citrix remote access portals commonly exploited in healthcare environments per CISA KEV catalog.
logsource:
category: firewall
product: paloalto
detection:
selection_cve:
cve|contains: 'CVE-2021-36260'
selection_app:
app|contains:
- 'hikvision'
- 'ultravnc'
- 'vnc'
condition: selection_cve or selection_app
falsepositives:
- Legitimate Hikvision camera management traffic
- Authorized VNC remote support sessions
level: high
tags:
- attack.initial_access
- attack.t1190
Tune by excluding known authorized VNC management subnets and Hikvision camera management IPs from your internal asset inventory. High false positive potential in environments with legitimate VNC usage; correlate with asset inventory to distinguish managed vs. unmanaged VNC endpoints.
T1133: External Remote Services (Initial Access) [P1]
The Change Healthcare breach leveraged compromised credentials against a Citrix remote access portal lacking MFA. Healthcare organizations broadly depend on remote access (VNC, RDP, Citrix) for clinical workflows and vendor support, creating persistent exposure. SonicWall recorded 13.3 million UltraVNC exploitation attempts against healthcare in the first five months of 2026.
Splunk SPL:
index=corelight sourcetype=corelight_conn (id.resp_p=5900 OR id.resp_p=5901 OR id.resp_p=5800 OR id.resp_p=5801 OR id.resp_p=443 OR id.resp_p=3389)
| eval is_external=if(cidrmatch("10.0.0.0/8", id.orig_h) OR cidrmatch("172.16.0.0/12", id.orig_h) OR cidrmatch("192.168.0.0/16", id.orig_h), "internal", "external")
| where is_external="external"
| stats count dc(id.orig_h) as unique_sources sum(orig_bytes) as total_bytes by id.resp_h, id.resp_p, service
| where count > 50
| sort -count
| table id.resp_h, id.resp_p, service, unique_sources, count, total_bytes
Elastic KQL:
(destination.port:(5900 OR 5901 OR 5800 OR 5801 OR 3389)) AND NOT source.ip:(10.0.0.0/8 OR 172.16.0.0/12 OR 192.168.0.0/16)
Sigma Rule:
title: External VNC or RDP Access to Healthcare Infrastructure
id: b2c3d4e5-6789-01bc-def0-234567890abc
status: experimental
author: RedSheepSec
date: 2026/07/10
description: Detects inbound connections from external IP addresses to VNC (5900-5901, 5800-5801) or RDP (3389) ports, which are common remote access vectors exploited in healthcare ransomware attacks.
logsource:
category: network_connection
product: zeek
detection:
selection:
dst_port:
- 5900
- 5901
- 5800
- 5801
- 3389
filter_internal:
src_ip|cidr:
- '10.0.0.0/8'
- '172.16.0.0/12'
- '192.168.0.0/16'
condition: selection and not filter_internal
falsepositives:
- Authorized vendor remote support sessions
- Legitimate telehealth or clinical remote access
level: high
tags:
- attack.initial_access
- attack.t1133
Build a baseline of authorized remote access source IPs and exclude them. Pay particular attention to VNC ports, as UltraVNC exploitation is extremely high-volume in healthcare. Correlate with MFA enforcement status on Citrix/VPN gateways.
T1078: Valid Accounts (Initial Access) [P2]
The Change Healthcare attack relied on compromised credentials to access a Citrix portal lacking MFA. Credential compromise combined with absent MFA remains a primary initial access vector for ransomware groups targeting healthcare, particularly through vendor and business associate accounts.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4624 Logon_Type=10
| eval hour=strftime(_time, "%H")
| stats count dc(src_ip) as unique_sources values(src_ip) as source_ips by Account_Name, Workstation_Name
| where count > 10 AND unique_sources > 3
| sort -count
| table Account_Name, Workstation_Name, unique_sources, source_ips, count
Elastic KQL:
event.code:"4624" AND winlog.event_data.LogonType:"10" AND NOT source.ip:(10.0.0.0/8 OR 172.16.0.0/12 OR 192.168.0.0/16)
Sigma Rule:
title: Multiple Source RDP Logon Indicating Credential Compromise
id: c3d4e5f6-7890-12cd-ef01-34567890abcd
status: experimental
author: RedSheepSec
date: 2026/07/10
description: Detects a single account performing RDP logons from multiple distinct source IPs, which may indicate compromised credentials being used from different locations, consistent with initial access patterns observed in healthcare ransomware attacks.
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
LogonType: 10
condition: selection
# Note - aggregation logic for multiple source IPs per account should be implemented at SIEM level
falsepositives:
- IT administrators using multiple jump boxes
- Shared service accounts for clinical applications
level: medium
tags:
- attack.initial_access
- attack.t1078
Focus on service accounts and vendor accounts that may lack MFA enforcement. Cross-reference with Citrix/VPN authentication logs. Accounts logging in from multiple geographically diverse IPs within short timeframes are high priority.
T1059.001: PowerShell (Execution) [P2]
Ransomware operators commonly leverage PowerShell for post-exploitation activities after gaining initial access through exploited vulnerabilities or compromised credentials. With 59% of 592 healthcare incidents involving ransomware, PowerShell-based execution is a high-probability TTP for the post-access phase of these attacks.
Splunk SPL:
index=powershell sourcetype="XmlWinEventLog" EventCode=4104
| eval script_lower=lower(ScriptBlockText)
| where match(script_lower, "(invoke-webrequest|downloadstring|downloadfile|invoke-expression|iex|encodedcommand|bypass|hidden|noprofile|net\.webclient|start-bitstransfer|invoke-mimikatz|invoke-shellcode)")
| stats count values(ScriptBlockText) as scripts by ComputerName, UserID
| where count > 0
| sort -count
| table ComputerName, UserID, count, scripts
Elastic KQL:
event.code:"4104" AND powershell.file.script_block_text:(*Invoke-WebRequest* OR *DownloadString* OR *DownloadFile* OR *Invoke-Expression* OR *IEX* OR *EncodedCommand* OR *-bypass* OR *-hidden* OR *Net.WebClient* OR *Invoke-Mimikatz*)
Sigma Rule:
title: Suspicious PowerShell Download or Execution Pattern in Healthcare Environment
id: d4e5f6a7-8901-23de-f012-4567890abcde
status: experimental
author: RedSheepSec
date: 2026/07/10
description: Detects PowerShell commands commonly used by ransomware operators for downloading payloads or executing malicious code, particularly relevant given 59% ransomware involvement rate in healthcare cyber incidents.
logsource:
product: windows
category: ps_script
detection:
selection_download:
ScriptBlockText|contains:
- 'Invoke-WebRequest'
- 'DownloadString'
- 'DownloadFile'
- 'Net.WebClient'
- 'Start-BitsTransfer'
selection_exec:
ScriptBlockText|contains:
- 'Invoke-Expression'
- 'IEX'
- 'Invoke-Mimikatz'
- 'Invoke-Shellcode'
selection_evasion:
ScriptBlockText|contains:
- 'EncodedCommand'
- '-bypass'
- '-hidden'
- '-noprofile'
condition: selection_download or selection_exec or selection_evasion
falsepositives:
- Legitimate system administration scripts
- Software deployment tools using PowerShell
level: medium
tags:
- attack.execution
- attack.t1059.001
Baseline legitimate PowerShell usage in the environment before deploying. Healthcare environments often use PowerShell for SCCM, Intune, and clinical application management. Whitelist known scripts by hash. Focus on clinical workstations and servers where PowerShell execution is not routine.
T1021.005: VNC (Lateral Movement) [P1]
SonicWall detected 13.3 million UltraVNC exploitation attempts across healthcare in the first five months of 2026. UltraVNC buffer overflow vulnerabilities enable both initial access and lateral movement. VNC is widely used in healthcare for remote clinical support and vendor access to medical devices.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" (EventCode=1 OR EventCode=3)
| search (EventCode=1 AND (Image="*ultravnc*" OR Image="*winvnc*" OR Image="*vncviewer*" OR OriginalFileName="*ultravnc*" OR OriginalFileName="*winvnc*")) OR (EventCode=3 AND (DestinationPort=5900 OR DestinationPort=5901 OR DestinationPort=5800 OR DestinationPort=5801))
| stats count by EventCode, Image, DestinationIp, DestinationPort, User, ComputerName
| sort -count
| table ComputerName, User, Image, DestinationIp, DestinationPort, EventCode, count
Elastic KQL:
(event.code:"1" AND (process.executable:*ultravnc* OR process.executable:*winvnc* OR process.executable:*vncviewer*)) OR (event.code:"3" AND destination.port:(5900 OR 5901 OR 5800 OR 5801))
Sigma Rule:
title: UltraVNC Process Execution or VNC Network Connection
id: e5f6a7b8-9012-34ef-0123-567890abcdef
status: experimental
author: RedSheepSec
date: 2026/07/10
description: Detects execution of UltraVNC binaries or outbound VNC connections, relevant to the 13.3 million UltraVNC exploitation attempts observed against healthcare in H1 2026.
logsource:
category: process_creation
product: windows
detection:
selection_process:
Image|contains:
- 'ultravnc'
- 'winvnc'
- 'vncviewer'
selection_original:
OriginalFileName|contains:
- 'ultravnc'
- 'winvnc'
condition: selection_process or selection_original
falsepositives:
- Authorized IT remote support using VNC
- Medical device vendor remote maintenance sessions
level: high
tags:
- attack.lateral_movement
- attack.t1021.005
Many healthcare environments legitimately use VNC for clinical device support. Build an authorized VNC endpoint list from your CMDB and asset inventory. Any VNC activity on endpoints not in that list should be treated as high priority. Monitor for UltraVNC specifically as it was the primary exploitation target.
T1486: Data Encrypted for Impact (Impact) [P1]
Approximately 59% of 592 healthcare incidents analyzed by Securin involved ransomware. SonicWall recorded 16.6 million ransomware detections across 10 active ransomware families targeting healthcare. Ransomware encryption of clinical systems directly impacts patient care, with nearly three in four U.S. healthcare organizations reporting care disruptions from cyberattacks.
Splunk SPL:
index=sysmon sourcetype="XmlWinEventLog" EventCode=11
| eval ext=lower(mvindex(split(TargetFilename, "."), -1))
| where ext IN ("encrypted", "locked", "crypt", "enc", "ransom", "pay", "onion", "readme")
| stats count dc(TargetFilename) as unique_files by ComputerName, User, Image
| where unique_files > 20
| sort -unique_files
| table ComputerName, User, Image, unique_files, count
Elastic KQL:
event.code:"11" AND file.extension:("encrypted" OR "locked" OR "crypt" OR "enc" OR "ransom")
Sigma Rule:
title: Mass File Creation with Ransomware Extension Indicators
id: f6a7b8c9-0123-45f0-1234-67890abcdef0
status: experimental
author: RedSheepSec
date: 2026/07/10
description: Detects mass creation of files with extensions commonly associated with ransomware encryption, relevant to the 16.6 million ransomware detections recorded against healthcare.
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|endswith:
- '.encrypted'
- '.locked'
- '.crypt'
- '.enc'
- '.ransom'
condition: selection
falsepositives:
- Legitimate encryption software
- Backup tools that create .enc files
level: critical
tags:
- attack.impact
- attack.t1486
This detection fires at the encryption stage, which may be late in the kill chain. Combine with earlier-stage detections (T1190, T1133, T1078) for layered coverage. Volume-based thresholding (unique_files > 20 within a short window) helps distinguish from legitimate encryption tools.
T1040: Network Sniffing (Credential Access) [P2]
Healthcare IoT devices running embedded operating systems on flat networks can be leveraged for credential sniffing. With 243 unique attack signatures targeting healthcare IoT devices, compromised devices on unsegmented networks can intercept clinical system credentials. This technique supports the broader credential theft and lateral movement patterns seen in healthcare ransomware chains.
Splunk SPL:
index=corelight sourcetype=corelight_conn
| eval src_subnet=mvindex(split(id.orig_h, "."), 0) . "." . mvindex(split(id.orig_h, "."), 1) . "." . mvindex(split(id.orig_h, "."), 2)
| eval dst_subnet=mvindex(split(id.resp_h, "."), 0) . "." . mvindex(split(id.resp_h, "."), 1) . "." . mvindex(split(id.resp_h, "."), 2)
| where src_subnet != dst_subnet
| lookup iot_device_list ip AS id.orig_h OUTPUT device_type
| where isnotnull(device_type)
| stats count dc(id.resp_h) as unique_destinations by id.orig_h, device_type, id.resp_p
| where unique_destinations > 10
| sort -unique_destinations
| table id.orig_h, device_type, id.resp_p, unique_destinations, count
| rename id.orig_h as IoT_Source, id.resp_p as Dest_Port
Elastic KQL:
event.dataset:"corelight.conn" AND source.ip:* AND NOT (destination.port:(443 OR 80 OR 53))
Sigma Rule:
title: IoT Device Anomalous Cross-Subnet Communication
id: a7b8c9d0-1234-56a1-2345-7890abcdef01
status: experimental
author: RedSheepSec
date: 2026/07/10
description: Detects IoT or medical devices communicating across network segments to unusual destinations, which may indicate compromised devices being used for reconnaissance or credential sniffing in unsegmented healthcare networks.
logsource:
category: network_connection
product: zeek
detection:
selection:
src_ip|cidr:
- '10.0.0.0/8'
filter_common:
dst_port:
- 443
- 80
- 53
condition: selection and not filter_common
falsepositives:
- Medical device firmware updates
- Legitimate clinical application cross-subnet traffic
level: medium
tags:
- attack.credential_access
- attack.t1040
This detection requires an IoT device inventory lookup table. If an iot_device_list lookup is not available, substitute with known medical device subnets. The goal is to identify IoT devices reaching outside their expected communication patterns, which could indicate compromise or poor segmentation.
T1570: Lateral Tool Transfer (Lateral Movement) [P2]
After initial access through exploited KEV vulnerabilities or compromised credentials, ransomware operators transfer tools laterally across healthcare networks. The flat network architectures common in healthcare (243 IoT attack signatures, legacy device segments) facilitate lateral movement. SMB-based file transfers to multiple hosts in short windows are strong indicators of ransomware staging.
Splunk SPL:
index=corelight sourcetype=corelight_smb_files action=SMB::FILE_WRITE
| stats count dc(id.resp_h) as unique_targets values(name) as filenames by id.orig_h
| where unique_targets > 5 AND count > 20
| sort -unique_targets
| table id.orig_h, unique_targets, count, filenames
Elastic KQL:
event.dataset:"corelight.smb_files" AND event.action:"SMB::FILE_WRITE"
Sigma Rule:
title: SMB File Write to Multiple Hosts Indicating Lateral Tool Transfer
id: b8c9d0e1-2345-67b2-3456-890abcdef012
status: experimental
author: RedSheepSec
date: 2026/07/10
description: Detects a single source writing files via SMB to multiple destination hosts, which may indicate ransomware staging or lateral tool transfer within a healthcare network.
logsource:
category: network_connection
product: zeek
detection:
selection:
action: 'SMB::FILE_WRITE'
condition: selection
falsepositives:
- Software distribution systems (SCCM, PDQ)
- Group Policy script deployment
- Legitimate file server operations
level: high
tags:
- attack.lateral_movement
- attack.t1570
Exclude known software distribution servers and SCCM/WSUS hosts from source IP filtering. Focus on sources that are workstations or clinical devices writing executables (.exe, .dll, .bat, .ps1) to multiple hosts.
Suricata Rules
SID 9000001: Detects inbound connection attempts to VNC ports (5900-5901) from external networks, indicative of UltraVNC exploitation attempts targeting healthcare infrastructure
alert tcp $EXTERNAL_NET any -> $HOME_NET 5900:5901 (msg:"REDSHEEPSEC - External VNC Connection Attempt to Healthcare Infrastructure"; flow:to_server,established; content:"RFB "; offset:0; depth:4; classtype:attempted-admin; sid:9000001; rev:1; metadata:created_at 2026_07_10, updated_at 2026_07_10;)
SID 9000002: Detects potential Hikvision camera exploitation attempts targeting CVE-2021-36260 command injection via HTTP
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"REDSHEEPSEC - Potential Hikvision CVE-2021-36260 Command Injection Attempt"; flow:to_server,established; content:"/SDK/webLanguage"; http_uri; content:"PUT"; http_method; classtype:web-application-attack; sid:9000002; rev:1; reference:cve,2021-36260; metadata:created_at 2026_07_10, updated_at 2026_07_10;)
SID 9000003: Detects inbound RDP connection attempts from external networks, relevant to credential-based initial access patterns in healthcare ransomware attacks
alert tcp $EXTERNAL_NET any -> $HOME_NET 3389 (msg:"REDSHEEPSEC - External RDP Connection Attempt to Healthcare Infrastructure"; flow:to_server; flags:S; threshold:type both, track by_src, count 5, seconds 60; classtype:attempted-admin; sid:9000003; rev:1; metadata:created_at 2026_07_10, updated_at 2026_07_10;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Palo Alto Firewall (PAN Threat Logs) | T1190 | index=firewall-pan sourcetype=pan:threat. Ensure threat prevention profiles are logging CVE-tagged alerts. Verify Hikvision and VNC application signatures are enabled. |
| Corelight/Zeek Network Metadata | T1133, T1021.005, T1040, T1570 | index=corelight. Requires corelight_conn, corelight_smb_files, corelight_http, corelight_ssl sourcetypes. Verify sensors cover segments with medical devices and remote access infrastructure. |
| Sysmon (Windows Endpoint) | T1021.005, T1486, T1570 | index=sysmon sourcetype=XmlWinEventLog. Requires EventID 1 (process creation), 3 (network connections), 11 (file creation). Verify Sysmon is deployed to clinical workstations and servers, not just standard IT endpoints. |
| Windows Security Event Logs | T1078 | index=winevent sourcetype=XmlWinEventLog:Security. Requires EventCode 4624 (logon), 4625 (failed logon), 5145 (network share). Ensure audit policies log Type 10 (RDP) logons. |
| PowerShell ScriptBlock Logging | T1059.001 | index=powershell sourcetype=XmlWinEventLog. Requires EventCode 4104 (ScriptBlock logging). Must be enabled via GPO: 'Turn on PowerShell Script Block Logging'. Verify coverage on clinical servers and workstations. |
| CrowdStrike EDR | T1486, T1059.001, T1021.005 | index=crowdstrike. Provides detection context for ransomware behaviors, suspicious process execution, and lateral movement. Verify sensor coverage includes medical device management servers. |
| Azure AD / Entra ID Sign-In Logs | T1078 | index=cloud-azure sourcetype=azure:monitor:aad. Required for detecting credential compromise against cloud-hosted remote access portals (Citrix Cloud, Azure VPN). Verify conditional access policy logging is enabled. |
| Suricata/IDS via Corelight | T1190 | index=corelight sourcetype=corelight_suricata_corelight. Ensure CVE-2021-36260 and VNC exploitation rules are loaded in the Suricata ruleset. |
Recommendations
- Conduct an immediate audit of all internet-facing assets against the current CISA KEV catalog, with priority remediation for CVE-2021-36260 (Hikvision command injection) and all UltraVNC buffer overflow CVEs. Enforce CISA BOD 22-01 per-CVE remediation deadlines.
- Deploy all Splunk, Sigma, and Suricata detections from this report across production SIEM and IDS/IPS instances. Prioritize the P1 detections for external VNC/RDP access, Hikvision exploitation, and ransomware file encryption indicators.
- Enumerate all Hikvision cameras and NVRs on the network using asset discovery tools (Runzero, Claroty, or Nmap service scanning for port 554/80/443 with Hikvision HTTP headers). Patch or isolate any devices running firmware vulnerable to CVE-2021-36260.
- Identify and inventory all VNC endpoints (UltraVNC, TightVNC, RealVNC) across the environment. Remove unauthorized VNC installations and ensure all authorized instances are patched against known buffer overflow vulnerabilities. Restrict VNC access to approved management subnets via firewall policy.
- Verify MFA enforcement on all remote access portals (Citrix, VPN concentrators, RDP gateways) used by internal staff and business associates. The Change Healthcare attack path exploited a Citrix portal lacking MFA; this specific control gap must be validated as closed.
- Implement or validate network segmentation between medical device VLANs, IoT camera segments, and the general enterprise network. Block outbound internet access from medical device segments except through explicit allow-list proxies. Deploy the IoT cross-segment communication detection from this report.
- Review all business associate agreements for cybersecurity requirements, particularly KEV remediation timelines and MFA enforcement, given that reporting indicates over 80% of stolen PHI records originate from third-party vendors.
- Establish a weekly KEV review cadence mapped to the vulnerability management program. Track mean-time-to-remediate for KEV entries as a distinct metric and report it to clinical and executive leadership as a patient safety indicator.
Sources
- Healthcare Cybersecurity Threats Persist in 2026 - eSecurity Planet
- SonicWall Research Sounds Code Red on Healthcare Cybersecurity - e-Channel News
- Healthcare Cybersecurity Outlook 2026 - Clearwater Security
- Proofpoint and Ponemon Institute Report - Impact of Cyberattacks on Patient Care
- Healthcare Sector Cyber Threat Intelligence Report Q1 2026 - Securin