logo

Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware

ID: 2baf3953-1867-5765-8200-da30b5efb097

STIX ID: report--2baf3953-1867-5765-8200-da30b5efb097

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-09-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft observed the Vanilla Tempest threat actor using INC Ransom (a RaaS) against U.S. healthcare, employing an intrusion chain that included Gootloader, a Supper backdoor, AnyDesk/MEGA, and lateral movement via RDP and WMI to deploy INC ransomware; the strain has been linked to multiple high-impact victims (including NHS Scotland and McLaren Health Care), and the INC encrypter source code has reportedly been offered for sale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.