KillSec Ransomware Attacking Healthcare Industry IT Systems
ID: 4bb31f34-0318-59e5-ac9f-b00774f07071
STIX ID: report--4bb31f34-0318-59e5-ac9f-b00774f07071
Feed Name: cybersecurityNews.com
KillSec is a newly observed ransomware campaign rapidly targeting healthcare organizations (initially in Brazil) by leveraging compromised software supply chains and misconfigured cloud buckets; infection commonly begins with a malformed PDF exploiting a zero-day to execute a PowerShell downloader that performs in-memory reflective DLL injection (into lsass.exe) and deploys an AES-256 encryption engine, enabling lateral movement via WinRM/RDP, persistent SYSTEM services, and the exfiltration and public leakage of sensitive medical data (~34 GB), prompting regulatory breach notifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
