惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
V
V2EX
T
The Blog of Author Tim Ferriss
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Hugging Face - Blog
Hugging Face - Blog
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
Recent Announcements
Recent Announcements
Vercel News
Vercel News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tailwind CSS Blog
美团技术团队
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Healthcare & Ransomware: A Different Type of Pandemic
Intel 471 · 2021-04-21 · via Intel 471 Blog

The healthcare industry is facing a pandemic on two fronts, COVID-19 on one, and ransomware on the other

.

The healthcare industry is worth more than $8.45 trillion in the global economy. The services it provides are the difference between life and death for many. It should come as no surprise then that these organizations are a prime target. This is true especially for cyber criminals using ransomware to carry out their malicious ends.

[hubspot type=cta portal=7924572 id=e7e7c860-1390-4fe6-a3f9-0c8d05dac52b]

These attacks, carried out by advanced adversaries, cripple healthcare institutions and facilities. They render networks unusable. The attacks prevent access to critical information used for patient care. And they can also cause loss of hard-earned reputation from leaked confidential information.

Healthcare organizations have always been a target of interest for cyber criminals due to their critical role in society. This targeting, however, has seen exponential increase since the beginning of the pandemic.

The evidence of this assault is staggering. Since November 2020 there has been a 45% increase in attacks targeting healthcare. This increase came on the heels of a previous 71% increase from only the month before. These attacks have also been widespread, from the US, Germany, Spain, UK, and hundreds of others around the world. And these attacks have not appeared to subside, even in the face of increased availability of the COVID-19 vaccine.

Amongst the largest perpetrators of these attacks have been the gangs behind the Ryuk and Sodinokibi ransomware. The damage these groups have caused is significant. In early 2020, a single compromise of Ryuk cost United Health Services more than $67 million dollars. Over the last year, the gang is believed to have amassed more than $150 million in Bitcoin ransomware payments.

Even government agencies have begun to ring the alarm bell.

In late 2020, several US government agencies, including CISA, the FBI, and HHS, issued a warning to healthcare organizations. Shortly after that UK's NCSC also issued a warning, saying:

“... Ransomware is a significant cyber risk and we continue to work closely with government and the NHS to ensure that we are taking all available measures to counter the threat...”

Canada, Australia, and even Interpol have all also followed suit, highlighting the severity of the situation.

The global COVID-19 crisis has only further complicated this on-going attack. Many hospitals have had to cope with rapidly changing environments. Temporary emergency facilities to deal with the pandemic were often not designed with security in mind. Additionally, many organizations are still triaging the situation around remote workers. This reality paints a frightening picture with a dire prognosis for infosec professionals.

How Healthcare Can Take a Proactive Approach to Defense

Many healthcare organizations are stretched thin, both from a resource and budgetary perspective. In spite of this, there are key considerations security personnel in healthcare should consider.

Take a Proactive Approach with Threat Hunting. A common feature of many compromised organizations is that they relied exclusively on reactive security. Even the best reactive security doesn't deter advanced adversaries. This is because many of these compromises are human-driven. Many of these adversaries also team up with criminal specialists. These specialists are capable of evading automated security controls using advanced techniques often days or weeks before the cyber criminals begin the the full attack. Healthcare organizations need to focus their efforts on proactive, human-led, threat hunting. This type of defense uses human-led hunt teams to identify suspicious and malicious activity. Automated security controls can detect traditional malicious code; but, it takes a human to hunt down human adversaries.

Move Beyond Indicators of Compromise (IoCs). Many organizations continue to rely heavily on reactive and outdated indicators of compromise . These IoCs are outdated in hours, and worthless in days. Adversaries will cycle through infrastructure and deploy bespoke malware avoiding detection by teams relying on IoCs. Healthcare security teams need to focus instead on adversaries tactics, techniques and procedures (TTPs) and behaviours. By detecting behaviours associated with lateral movement, internal reconnaissance, and privilege escalation it makes it harder for adversaries to conceal themselves in an environment. This gives healthcare security teams the time needed to detect the cyber criminals before they detonate the ransomware in the environment.

The Endpoint is the New Castle. The conventional approach to security is to treat the organization as a castle and defend it. In today's remote workforce, that centralized, one-size-fits-all, approach doesn't always hold true. Instead, organizations need to look at every endpoint as its own castle. And every castle is unique. Security teams need access to threat content designed for their unique environments.

[hubspot type=cta portal=7924572 id=7e10db25-ed3c-47d3-973d-eafc0a6af241]