INC Ransom group claims a month-old cyberattack on Tri-City Medical Center, demanding urgent

Continue reading
INC Ransom group claims responsibility for a cyberattack on Tri-City Medical Center in Oceanside, California. The 388-bed hospital detected unauthorized activity on November 9th, leading to a diversion of emergency patients. The group now threatens to expose sensitive data, adding a new layer of urgency to the situation.
INC Ransom, a newcomer to the ransomware world since July 2023, executed a multi-pronged attack on Tri-City Medical Center. The Proof Pack released by the group includes patient medical records, surgical forms, financial data, and communications with the California State Department of Health.
The hospital, a crucial healthcare provider in North San Diego County, faced significant disruptions, temporarily halting elective procedures and initiating an Internal Disaster diversion with San Diego County's Office of Emergency Services for at least five days.
INC Ransom, a multi-extortion operation, encrypts and steals data while threatening victims with public exposure. The group, active across various sectors, employs spear-phishing emails and exploits vulnerabilities like the Citrix Bleed zero-day vulnerability.
INC Ransom deploys a range of tools in its attacks, including NETSCAN.EXE for network profiling, MEGAsyncSetup64.EXE for file sharing, ESENTUTL.EXE for database management, and AnyDesk.exe for remote desktop access. The group's ransom notes, written in both .TXT and .HTML formats, indicate a personalized approach for each victim.
The group exploited the Citrix Netscaler flaw, even after a warning from the US Department of Health and Human Services. Criminal groups, including the Russian-linked LockBit ransom group, capitalized on this vulnerability, highlighting the critical need for prompt patching.
Tri-City Medical Center, a cornerstone of healthcare in North San Diego County, has responded proactively to the INC Ransom attack. In an undated blog post on its website, the hospital reassured the community of its commitment to restoring services while prioritizing patient health and wellness.
Upon discovering the breach, Tri-City swiftly took its systems offline, a crucial step to halt the unauthorized activity. The hospital's collaboration with third-party cybersecurity specialists and law enforcement underscores the gravity of the situation. The investigation aims not only to understand the extent of the breach but also to implement preventive strategies against future threats.
Tri-City's coordination with county first responder agencies and neighboring healthcare facilities is commendable. This collaborative effort helps manage the overflow of patients and ensures emergency services continue seamlessly despite the challenges posed by the cyberattack.
Understanding INC Ransom's operational signature is vital for cybersecurity professionals and organizations looking to bolster their defenses. The group's emergence in July 2023 and subsequent targeting of diverse industries necessitated a comprehensive understanding of their tactics.
INC Ransom's indiscriminate targeting of healthcare, education, and government sectors raises concerns about the breadth of its impact. With seven victims listed on their TOR-based blog, including two from the healthcare industry, the group's reach extends across different domains.
The group's reliance on spear-phishing emails and exploitation of vulnerabilities, such as the Citrix Bleed zero-day, highlights the evolving nature of cyber threats. Organizations must stay vigilant, promptly addressing known vulnerabilities and adopting proactive security measures.
INC Ransom's payloads exhibit a sophisticated approach with support for various command-line arguments. Understanding these arguments, such as targeting specific files or directories, aids in developing more robust detection and mitigation strategies.
--file Target a file directly for encryption (path)
--dir Target a directory for encryption (path)
--sup Stop using process
--ens Encrypt network shares
--lhd Local hidden drives (encrypt hidden boot and recovery volumes)
--debug Output console-style debug loggingThis detailed breakdown offers cybersecurity professionals valuable insights into the nuances of INC Ransom's encryption methods.
INC Ransom's personalized approach, assigning unique identifying numbers to each victim, adds a layer of complexity. Ransom notes in both .TXT and .HTML formats, coupled with automatic attempts to print on connected devices, demonstrate the group's determination to extract ransoms.

Suno AI breach exposes data linked to 55 million users and reveals deeper concerns around AI training data security provenance and supply chain risks