Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware
ID: 2baf3953-1867-5765-8200-da30b5efb097
STIX ID: report--2baf3953-1867-5765-8200-da30b5efb097
Feed Name: Bleeping Computer
Threat Score
Microsoft observed the Vanilla Tempest threat actor using INC Ransom (a RaaS) against U.S. healthcare, employing an intrusion chain that included Gootloader, a Supper backdoor, AnyDesk/MEGA, and lateral movement via RDP and WMI to deploy INC ransomware; the strain has been linked to multiple high-impact victims (including NHS Scotland and McLaren Health Care), and the INC encrypter source code has reportedly been offered for sale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
