European ransomware group strikes US hospital networks, analysts warn
Full article602 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
“UNC1878 is one of most brazen, heartless and disruptive threat actors I’ve observed over my career,” Mandiant's Charles Carmakal said.
An Eastern European cybercriminal group has conducted ransomware attacks at multiple U.S. hospitals in recent days in some of the most disruptive cyber-activity in the sector during the coronavirus pandemic, cybersecurity company FireEye said Wednesday.
The group, which FireEye calls UNC1878, has been deploying Ryuk ransomware and taking multiple hospital IT networks offline, said Charles Carmakal, senior vice president of Mandiant, FireEye’s incident response arm.
“UNC1878 is one of most brazen, heartless and disruptive threat actors I’ve observed over my career,” Carmakal said. The group’s activity “is deliberately targeting and disrupting U.S. hospitals, forcing them to divert patients to other healthcare providers,” he said.
The company did not detail any specific attacks, or the timing of the activity it says it observed.
The announcement coincides with multiple reported ransomware incidents, including an attack earlier this week on Oregon’s Sky Lakes Medical Center. The medical center carried on with emergency and urgent care, but said that “communications with the medical center will be a little complicated, however, until systems are restored.”
Ransomware also infected the IT networks of hospitals in New York state, forcing the Canton-Potsdam, Massena and Gouverneur hospitals to revert to back-up processes. A new variant of Ryuk was reportedly involved.
The FBI and departments of Homeland Security and Health and Human Services convened a phone call on Wednesday to brief the private sector on the attacks. An invitation to the call said it would cover “credible information of an increased and imminent cybercrime threat to US hospitals and healthcare providers.”
The ransomware incidents this week follow a reported Ryuk ransomware attack on Universal Health Services, which describes itself as one of the largest health care providers in the U.S.
Cybercriminals have continued to lock down IT systems at hospitals and demand payoffs, despite the deadly coronavirus pandemic. U.S. federal agencies and private companies have called in reinforcements to try to blunt the impact of the attacks.
Cybersecurity professionals around the world have been so concerned by the hacking of health care organizations that they have volunteered their time to protect them. For its part, the U.S. Cybersecurity and Infrastructure Security Agency in July hired Josh Corman, a health care cybersecurity specialist, to bolster the agency’s work to defend the sector from attacks.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ransomware-hospitals-ryuk-fireeye/