Threat reportRansomwareTL-2026-3127
Healthcare Sector Ransomware Targeting and Expanding Attack Surface (Qilin, Akira, DragonForce, LockBit, The Gentlemen)
Healthcare Sector Ransomware Targeting and Expanding Attack (TL-2026-3127), also tracked as Healthcare Ransomware Expanding Attack Surface, is a high-severity ransomware operation, first published 2026-10-09. It is attributed to Qilin with medium confidence, affects Healthcare sector EHR, imaging, billing, patient portals, telemedicine, references 12 CVEs (CVE-2024-1708, CVE-2024-55591, CVE-2025-32433), maps to 18 MITRE ATT&CK techniques (T1003.001, T1021.001, T1021.002), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 12Referenced vulnerabilities
- Techniques
- 18MITRE ATT&CK
- Actors
- 4Qilin
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-3127
- Threat ID
- TL-2026-3127
- Also known as
- Healthcare Ransomware Expanding Attack Surface
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Qilin, Akira, DragonForce, The Gentlemen
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, manufacturing, business-services, energy, technology
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Healthcare Sector Ransomware Targeting and Expanding Attack
Malware and tooling: AgendaCrypt, Akira, AnyDesk, Cobalt Strike, DragonForce, G-BOT, LockBit, MimiKatz, SystemBC - S9001, the gentlemen, AnyDesk, Cobalt Strike
How Healthcare Sector Ransomware Targeting and Expanding Attack works
Flare reports healthcare is consistently among the top five most-targeted sectors in an analysis of 1,700+ ransomware attacks over two months, with roughly 80% of observed attacks against US organizations. Qilin, The Gentlemen, Akira, DragonForce and LockBit are the named operators; vendor and government reporting documents their intrusion tradecraft (edge-device exploitation, stolen credentials, remote-management tooling, Cobalt Strike/Rclone, BYOVD, double extortion).
Flare's 2026-10-08 analysis (Assaf Morag) frames healthcare as cybercrime's highest-value target: the FBI IC3 reported 460 ransomware attacks and 182 data breaches against US healthcare in 2025, and healthcare ranked in the top five sectors across 1,700+ ransomware attacks observed over a two-month window, with about 80% of them against US organizations. Protected health information is described as the most expensive PII on the dark web because medical identities cannot be reissued and can be monetized for years. The article cites studies of increased in-hospital mortality during ransomware incidents, and notes ENISA figures that ransomware accounted for 54% (2023) and 45% (2024) of European health-sector incidents. The article itself contains no CVEs, IOCs or new TTPs; technical detail below is drawn from the cross-referenced vendor and government reporting on each named group.
Initial access cited by Flare: phishing, infostealer-harvested staff credentials, browser cookies, session tokens and MFA artifacts, exposed RDP, vulnerable VPN and unpatched edge devices, third-party vendor access, and cloud misconfigurations. Structural weaknesses that amplify impact are legacy and unpatchable Windows/medical systems, flat networks, shared clinical accounts, inconsistent MFA, broad contractor access, incomplete asset inventories and poor IoMT telemetry. Emerging concerns include prompt injection against clinical AI tools, shadow AI, and fraud schemes such as NEMT ghost billing. Flare also references APT29 (COVID-19 vaccine research targeting, 2020), APT40 (China MSS, biomedical/virus-research targeting) and APT10 (healthcare and biotechnology) as nation-state context; these are background and not attributed to the ransomware activity.
Group tradecraft from corroborating sources: CISA's #StopRansomware advisory on Akira (published 2024-04-18, updated 2025-11-13) lists exploitation of Cisco, Veeam, SonicWall, VMware and Windows CVEs, VPNs without MFA, tools such as Mimikatz, Cobalt Strike, AnyDesk, Rclone, WinSCP, Ngrok, AdFind and Impacket, and roughly $244M in proceeds as of late September 2025. The Gentlemen (PRODAFT: Phantom Mantis / LARVA-368; Microsoft: Storm-2697) exploit FortiGate and other edge devices (CVE-2024-55591, CVE-2025-32433, CVE-2025-33073), use NetExec and related AD tooling, EDR-killer/BYOVD tooling, a modified Velociraptor and G-BOT for C2, GPO-based deployment, and a Go locker (X25519 + XChaCha20) with a --spread worm option for Windows, Linux and ESXi. DragonForce is a RaaS cartel (LockBit 3.0/Conti-derived encryptor) using help-desk social engineering, Cobalt Strike, SystemBC, Mimikatz, AdFind, SoftPerfect and Rclone. Qilin (per Security Arsenal reporting) abuses ConnectWise ScreenConnect (CVE-2024-1708), valid credentials from initial access brokers, Cobalt Strike, PsExec and Rclone, exfiltrating before encryption.
MITRE ATT&CK techniques used in TL-2026-3127
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory; T1539 Steal Web Session Cookie
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares
Execution
T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1133 External Remote Services
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing
Command and Control
Impact
T1490 Inhibit System Recovery; T1657 Financial Theft
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
defense-impairment
T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs
Affected products and versions in Healthcare Sector Ransomware Targeting and Expanding Attack
- Healthcare sector — EHR, imaging, billing, patient portals, telemedicine and IoMT systems
Vulnerable versions: Legacy/unpatched Windows and unsupported medical software; Flat networks without segmentation - Fortinet — FortiGate (CVE-2024-55591)
Vulnerable versions: Unpatched FortiOS
Fixed in: Vendor-patched FortiOS - ConnectWise — ScreenConnect (CVE-2024-1708)
Vulnerable versions: Unpatched ScreenConnect
Fixed in: Vendor-patched ScreenConnect - SonicWall / Veeam / Cisco / VMware — VPN, backup and ESXi CVEs listed in CISA Akira advisory
Vulnerable versions: Unpatched deployments
Fixed in: Vendor-patched releases
Remediation for Healthcare Sector Ransomware Targeting and Expanding Attack
Patches
- Apply vendor fixes for CVE-2024-40766 (SonicWall), CVE-2024-40711 (Veeam), CVE-2024-37085 (VMware ESXi), CVE-2023-20269 (Cisco), CVE-2024-55591 (Fortinet), CVE-2024-1708 (ConnectWise ScreenConnect)
Immediate actions
- Patch internet-facing VPN, firewall, remote-management and mail systems; prioritize CVEs listed in the CISA Akira advisory and CVE-2024-55591, CVE-2024-1708
- Enforce phishing-resistant MFA on all VPN, RDP, email and remote-access paths and review exposed RDP
- Hunt for Rclone, WinSCP, AnyDesk, ScreenConnect, Velociraptor and Cobalt Strike activity outside approved use
- Revoke sessions and reset credentials for staff appearing in infostealer logs
Workarounds
- Restrict management interfaces to VPN or allow-listed addresses
- Disable unused remote-access tools and legacy protocols where patching is blocked by vendor certification
Longer-term hardening
- Segment flat clinical and IoMT networks and monitor east-west traffic
- Maintain offline, immutable backups of critical data and test restoration
- Continuously monitor dark-web and stealer-log exposure of staff credentials and PHI
- Tighten third-party and contractor access and session-token governance
- Enable EDR tamper protection and block vulnerable signed drivers (BYOVD)
CVEs associated with Healthcare Sector Ransomware Targeting and Expanding Attack
CVE-2024-1708, CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, CVE-2020-3259, CVE-2020-3580, CVE-2023-20269, CVE-2023-28252, CVE-2024-37085, CVE-2023-27532, CVE-2024-40711, CVE-2024-40766
Weaknesses (CWE) in Healthcare Sector Ransomware Targeting and Expanding Attack
Timeline of Healthcare Sector Ransomware Targeting and Expanding Attack
- CISA, FBI and partners publish the original #StopRansomware advisory on Akira ransomware (AA24-109A).
- The Gentlemen begin activity as an affiliate-driven double-extortion operation (March 2025), previously using other RaaS programs.
- First The Gentlemen ransomware sample is uploaded to VirusTotal.
- CISA and partners update the Akira advisory with new IOCs, TTPs and detection methods; Akira proceeds reported at about $244M as of late September 2025.
- Internal Rocket.Chat infrastructure of The Gentlemen is leaked following a compromise linked to hosting provider 4VPS (May 2026).
- Qilin posts about 15 victims in roughly five days (June 2-5, 2026), about 20% in healthcare.
- The Hacker News reports The Gentlemen have claimed 478 victims and account for about 10% of ransomware activity in April 2026.
- Barracuda publishes analysis of The Gentlemen, confirming active operations as of 2026-08-14.
- Flare publishes its analysis of healthcare ransomware targeting across 1,700+ attacks, naming Qilin, The Gentlemen, Akira, DragonForce and LockBit.
Sources cited for Healthcare Sector Ransomware Targeting and Expanding Attack
- Healthcare Is Cybercrime's Highest-Value Target: Ransomware, Exposure, and the Expanding Attack Surface (Flare)
- CISA #StopRansomware: Akira Ransomware (AA24-109A)
- CISA and Partners Release Advisory Update on Akira Ransomware
- The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm (The Hacker News)
- The Gentlemen ransomware: Inside one of the fastest-growing extortion operations (Barracuda)
- DragonForce Ransomware attacks on retail giants (Picus Security)
- Threat Intelligence Report: DragonForce (Centre for Cybersecurity Belgium)
- Qilin Ransomware global surge in healthcare and energy sectors (Security Arsenal)
- Agencies warn healthcare sector to bolster defenses against Akira ransomware (This Week Health)
Detection coverage for TL-2026-3127
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3127 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.