FBI Warns U.S. Healthcare Sector of Targeted BlackCat Ransomware Attacks
ID: 037f9c85-cfcd-5a77-ae0d-5ae377b38a62
STIX ID: report--037f9c85-cfcd-5a77-ae0d-5ae377b38a62
Feed Name: The Hacker News
U.S. government agencies (FBI, CISA, HHS) warn of a resurgence of BlackCat/ALPHV ransomware targeting the healthcare sector and other critical infrastructure after law enforcement disruptions; the group regained leak sites and continues operations. The report highlights active attacks (including against Optum and other large organizations), weaponization and mass exploitation of ConnectWise ScreenConnect vulnerabilities, novel attacker tools and tactics (MrAgent for ESXi, Linux RaaS like Kryptina, sale of network access), and continued widespread exposure with thousands of potentially vulnerable ScreenConnect hosts observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
