Home
Elezar
Sol Threat Intelligence

June 2026
Healthcare and Hospitals
Regional Sector Brief

Download PDF
1 Jun to 30 Jun 20263 regional assessments4 pages per regionPrepared by Kaartheeswaran Ravichandran
A futuristic hospital complex protecting clinical systems from a cyber intrusion
Americas
Executive Summary
Specialized healthcare attack pipelines dominate the most heavily documented region

The Americas Healthcare and Hospitals sector had the strongest and most detailed intelligence coverage in the source set. Insomnia targeted US healthcare through encryptor-free data theft and WSUS abuse. Sinobi focused on mid-market health systems through SonicWall and MSP credentials. INC Ransomware expanded BYOVD EDR termination and Veeam credential theft, while the Code Blue assessment documented 233 million exposed records, 35 breaches and 37 weaponized CVEs across the broader healthcare landscape. Pediatric hospitals remained high-value targets because stolen child identity data can retain criminal value for more than a decade.

Key Insights
1
Insomnia targeted US healthcare with data theft only and used WSUS for artifact-light lateral movement.
2
Sinobi exceeded 250 victims and used SonicWall VPN and MSP credentials as its primary entry path.
3
INC Ransomware exceeded 800 victims and introduced ProcessTerminator.exe with three vulnerable drivers.
4
A dedicated Veeam credential dumper targeted healthcare backup infrastructure directly.
5
Fortinet CVE-2024-55591 was the most-referenced healthcare vulnerability in the macro-analysis.
6
Pediatric healthcare remained a priority for Rhysida, INC, LockBit and Vanilla Tempest.
Attack chains, vulnerabilities and indicators
CVEProductSeverityJune context
CVE-2024-55591Fortinet FortiOS / FortiProxyCriticalMost-cited healthcare CVE
CVE-2024-53704SonicWall SSL VPNCriticalSinobi authentication bypass
CVE-2024-40766SonicWallHighImproper access control and migration risk
CVE-2023-3519Citrix NetScalerCriticalINC initial access
CVE-2023-48788Fortinet EMSCriticalINC exploitation
CVE-2025-5777Citrix NetScalerCriticalINC initial access
CVE-2020-1472Windows ZerologonCriticalLegacy hospital AD takeover risk
Insomnia healthcare extortion
Attack PathELEZAR
01
Purchase infostealer credentials
T1650
02
Authenticate with valid accounts
T1078
03
Abuse WSUS for lateral movement
T1072
04
Collect patient and administrative data
T1005
05
Exfiltrate over web services
T1567
06
Publish data freely with no decryptor or negotiation
T1657
Sinobi mid-market hospital intrusion
Attack PathELEZAR
01
Compromised MSP SonicWall credentials
T1133
02
RDP into file server
T1078.002
03
Uninstall Carbon Black EDR
T1562.001
04
Create rogue admin and domain-admin accounts
T1136.001
05
Discover backups and network shares
T1083
06
RClone and WinSCP exfiltration
T1567.002
07
Curve25519 and AES encryption with .SINOBI extension
T1486
INC healthcare ransomware
Attack PathELEZAR
01
Public-app or remote-access compromise
T1190
02
ProcessTerminator.exe drops vulnerable drivers
T1562.001
03
Kill EDR with filwfp.sys, filnk.sys and fildds.sys
04
Veeam-Get-Creds.ps1 extracts backup credentials
T1003
05
Network discovery and cloud exfiltration
T1046 · T1567.002
06
DeviceIoControl-based recovery inhibition
T1490
07
Encryption and double extortion
T1486

Selected indicators

TypeIndicatorAttribution
Onioni62huw7ve22rpyw6lnq3kmfump2dmsg4xpveec3ere73njwatrz74gad[.]onionInsomnia DLS
Filerclone-ssh.conf / bin.exe / .SINOBISinobi
SHA2561b2a1e41a7f65b8d9008aa631f113cef36577e912c13f223ba8834bbefa4bd14Sinobi
FileProcessTerminator.exe / Veeam-Get-Creds.ps1INC
Driverfilwfp.sys / filnk.sys / fildds.sysINC BYOVD
FileINC-README.txtINC ransom note
Domainincblog[.]suINC leak site
Prioritized defensive guidance

Recommendations are calibrated for clinical systems, EHR and PACS environments, hospital Active Directory, remote-access appliances, backup infrastructure, MSP dependencies and patient-safety continuity.

Immediate: act within 72 hours
1. Audit WSUS administration and out-of-window deployments.
2. Patch SonicWall CVE-2024-53704 and CVE-2024-40766.
3. Block INC ProcessTerminator.exe and its vulnerable drivers.
Urgent: act within 2 weeks
1. Restrict Veeam SQL access and protect backup credentials.
2. Deploy infostealer detection on clinical endpoints.
3. Patch Fortinet CVE-2024-55591.
4. Review all MSP remote access and remove over-privileged accounts.
Strategic uplift
1. Create an Insomnia-specific data-theft response playbook.
2. Review pediatric hospital data segmentation and Discord access.
3. Reduce single-vendor clearinghouse dependency and isolate critical workflows.
4. Detect DeviceIoControl-based recovery inhibition and monitor healthcare credential leaks.
June source reports: HivePro Insomnia and Sinobi reporting, HiveForce Labs Code Blue analysis, Acronis INC ransomware research and PolySwarm pediatric healthcare analysis.
EMEA
Executive Summary
Ransomware, FortiGate credential theft and Teams vishing converge on hospitals

EMEA Healthcare and Hospitals faced a June threat environment shaped by ransomware-as-a-service, perimeter credential theft and social engineering. The Gentlemen emerged as the most operationally important ransomware group, with confirmed healthcare targeting, a documented healthcare case study, European infrastructure and domain-wide GPO deployment. FortiBleed confirmed dedicated European credential collection from FortiGate environments, while Microsoft Teams vishing campaigns directly targeted healthcare employees and executed Kerberoasting during live support impersonation sessions. Insomnia and pediatric-focused ransomware activity added further data-extortion and long-duration identity-theft risk.

Key Insights
1
The Gentlemen reached top-10 ransomware status and documented healthcare targeting through a full enterprise kill chain.
2
FortiBleed operator infrastructure included a dedicated results_EU directory for harvested FortiGate credentials.
3
Microsoft Teams vishing directly targeted healthcare staff and progressed to Kerberoasting in a single call.
4
Insomnia targeted healthcare through data theft only, making backup recovery irrelevant.
5
Rhysida, INC, LockBit and Vanilla Tempest remained active against pediatric healthcare.
6
The wider June corpus rose from 164 to 455 reports, increasing exposure across all healthcare attack surfaces.
Attack chains, vulnerabilities and indicators
CVEProductSeverityJune context
CVE-2024-55591Fortinet FortiOS / FortiProxyCriticalHealthcare perimeter exposure
CVE-2025-22457Ivanti Connect SecureCriticalRemote clinical access risk
CVE-2025-31324SAP NetWeaverCriticalHospital enterprise application risk
CVE-2026-35273Oracle PeopleSoftCriticalHospital HR and finance exposure
The Gentlemen healthcare intrusion
Attack PathELEZAR
01
Internet-facing VPN or firewall compromise
T1190
02
AD enumeration with SharpADWS
T1087.002
03
Go backdoor over TCP 9443 and Yamux
T1095
04
BYOVD EDR termination
T1562.001
05
NETLOGON and SYSVOL ransomware deployment
T1484.001
06
gpupdate /force across domain
07
Hyper-V shutdown, shadow-copy deletion and encryption
T1486
FortiBleed credential factory
Attack PathELEZAR
01
Passive FortiGate packet capture
T1040
02
Extract NTLM, Kerberos, RADIUS and session material
03
Credential validation and spraying
T1110.003
04
SPN and AS-REP enumeration
T1558.003
05
DFS and SMB collection
T1039
06
Large-scale exfiltration to operator infrastructure
T1020
Teams vishing to Kerberoasting
Attack PathELEZAR
01
External Teams contact
02
IT-helpdesk impersonation call
T1566.004
03
Quick Assist or TeamViewer session
T1219
04
PowerShell SPN queries
T1059.001
05
$krb5tgs$23$ hash extraction
T1558.003
06
Archive and exfiltration to file-sharing service
T1567

Selected indicators

TypeIndicatorAttribution
IP81[.]177[.]215[.]15:9443The Gentlemen backdoor C2
Filegentle.exe / deploy_gpo.ps1 / ScheduledTasks.xmlThe Gentlemen
TaskUpdateUser / TaskSystemThe Gentlemen persistence
IP193[.]8[.]187[.]42 / 85[.]11[.]187[.]8FortiBleed
Path/root/sniff/base/results_EU/FortiBleed European results
Domainhelpdeskwindowsfamily[.]onmicrosoft[.]comTeams vishing
Pattern$krb5tgs$23$Kerberoasting output
Prioritized defensive guidance

Recommendations are calibrated for clinical systems, EHR and PACS environments, hospital Active Directory, remote-access appliances, backup infrastructure, MSP dependencies and patient-safety continuity.

Immediate: act within 72 hours
1. Rotate FortiGate VPN credentials and revoke active sessions.
2. Block The Gentlemen C2 and hunt its backdoor, tasks and registry persistence.
3. Restrict Teams external access and prohibit unverified remote-support sessions.
Urgent: act within 2 weeks
1. Protect SYSVOL, NETLOGON and GPO from unauthorized modification.
2. Block The Gentlemen BYOVD drivers and Defender-disabling changes.
3. Restrict WSUS administration to approved service accounts.
4. Block unauthorized file-sharing and Discord-based exfiltration channels.
Strategic uplift
1. Detect bulk Kerberos service-ticket requests and weak SPN accounts.
2. Include live memory capture in ransomware response for potential Gentlemen key recovery.
3. Review pediatric patient-data segmentation and long-term identity risks.
4. Deploy Yamux and TCP 9443 network detection.
June source reports: Kaspersky and Dark Atlas reporting on The Gentlemen, Arctic Wolf FortiBleed analysis, CyberProof Teams vishing research, HivePro Insomnia reporting and PolySwarm pediatric healthcare analysis.
APAC
Executive Summary
Global healthcare threat patterns apply, but June regional reporting remains limited

APAC Healthcare and Hospitals faced a materially elevated threat environment in June 2026, but the supplied source set contained no APAC-specific healthcare incident report for the month. The principal intelligence source was HiveForce Labs' global healthcare analysis, which documented 35 disclosed breaches, 37 exploited CVEs and approximately 233 million exposed records from January 2025 through June 2026. Regional relevance is strongest where actor evidence is direct, particularly Lazarus Group's adoption of Medusa RaaS and the exposure of APAC hospitals to the same internet-facing appliance, credential-stealer and double-extortion attack paths. This section keeps confirmed reporting separate from regional inference.

Key Insights
1
No June 2026 report in the supplied material names a confirmed APAC healthcare victim.
2
Lazarus Group's adoption of Medusa RaaS is the strongest actor-level development with direct APAC relevance.
3
Double-extortion by Medusa, Interlock and Anubis remained the dominant global healthcare attack model.
4
Lumma, StealC and Rhadamanthys represented 24 percent of healthcare malware in the analysis window.
5
Seventy-eight percent of exploited CVEs were already listed in CISA KEV, showing patch lag rather than zero-days as the main vulnerability.
6
APAC nation-state campaigns active in adjacent sectors increased proximity risk to health ministries and state-owned hospital networks.
Attack chains, vulnerabilities and indicators
CVEProductSeverityJune context
CVE-2024-55591Fortinet FortiOS / FortiProxyCriticalMost-referenced healthcare CVE in the source analysis
CVE-2025-22457Ivanti Connect SecureCriticalRelevant to hospital remote-access infrastructure
CVE-2025-31324SAP NetWeaverCriticalHospital administrative platform exposure
CVE-2026-35273Oracle PeopleSoftCriticalHospital HR and finance systems potentially exposed
Healthcare double-extortion
Attack PathELEZAR
01
Exploit public-facing VPN, firewall or gateway
T1190
02
Stealer-harvested credentials or valid accounts
T1078.002
03
Web shell, Windows service or Run-key persistence
T1505.003
04
RDP and SMB lateral movement
T1021.001
05
Process injection and security impairment
T1055
06
Patient-data exfiltration over C2
T1041
07
EHR encryption, backup deletion and service disruption
T1486 · T1490
Credential-stealer pipeline
Attack PathELEZAR
01
Malicious download or endpoint compromise
T1204.002
02
Browser credential and cookie theft
T1555.003
03
VPN or domain credential replay
T1078
04
Internal access to clinical networks
T1021
05
Ransomware operator hand-off
06
Data theft and encryption
T1041 · T1486
Anubis destructive impact
Attack PathELEZAR
01
Initial access and lateral movement
02
Disable defenses and stop services
T1562 · T1489
03
Exfiltrate clinical and patient data
T1041
04
Delete recovery artifacts
T1490
05
Encrypt and irreversibly destroy data
T1486
06
Clinical downtime and patient-safety impact
T1485

Selected indicators

TypeIndicatorAttribution
MD5944153fb9692634d6c70899b83676575Lazarus-linked healthcare activity
MD5efc80697aa58ab03a10d02a8b00ee740Healthcare threat campaign
SHA1c12c4d58541cc4f75ae19b65295a52c559570054Healthcare threat campaign
SHA25628c3c50d115d2b8ffc7ba0a8de9572fbe307907aaae3a486aabd8c0266e9426fHealthcare threat campaign
SHA2564a97599ff5823166112d9221d0e824af7896f6ca40cd3948ec129533787a3ea9Healthcare threat campaign
Prioritized defensive guidance

Recommendations are calibrated for clinical systems, EHR and PACS environments, hospital Active Directory, remote-access appliances, backup infrastructure, MSP dependencies and patient-safety continuity.

Immediate: act within 72 hours
1. Patch Fortinet CVE-2024-55591 across hospital perimeter systems.
2. Audit Ivanti, Citrix and Palo Alto remote-access appliances for compromise.
3. Block and hunt Lazarus and Medusa indicators in endpoint tooling.
Urgent: act within 2 weeks
1. Deploy infostealer detection on clinical staff endpoints.
2. Protect Volume Shadow Copies and detect recovery-inhibition commands.
3. Restrict RDP to jump hosts and enable Network Level Authentication.
4. Validate offline backups for EHR, PACS, pharmacy and billing systems.
Strategic uplift
1. Patch PeopleSoft CVE-2026-35273 on hospital administrative systems.
2. Audit patient-facing applications for web shells and unauthorized scripts.
3. Create clinical-IT ransomware playbooks with manual fallback procedures.
4. Enable enhanced PowerShell logging and regional healthcare threat sharing.
June source reports: HiveForce Labs, Code Blue: U.S. Healthcare Under Cyber Siege, 15 June 2026, with clearly identified APAC regional inference where no local victim reporting existed.