Threat reportRansomwareTL-2026-3127

Healthcare Sector Ransomware Targeting and Expanding Attack Surface (Qilin, Akira, DragonForce, LockBit, The Gentlemen)

highACTIVE

Healthcare Sector Ransomware Targeting and Expanding Attack (TL-2026-3127), also tracked as Healthcare Ransomware Expanding Attack Surface, is a high-severity ransomware operation, first published 2026-10-09. It is attributed to Qilin with medium confidence, affects Healthcare sector EHR, imaging, billing, patient portals, telemedicine, references 12 CVEs (CVE-2024-1708, CVE-2024-55591, CVE-2025-32433), maps to 18 MITRE ATT&CK techniques (T1003.001, T1021.001, T1021.002), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
12Referenced vulnerabilities
Techniques
18MITRE ATT&CK
Actors
4Qilin
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-3127

Threat ID
TL-2026-3127
Also known as
Healthcare Ransomware Expanding Attack Surface
Severity
HIGH
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Qilin, Akira, DragonForce, The Gentlemen
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health, manufacturing, business-services, energy, technology
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
26

Malware and tooling in Healthcare Sector Ransomware Targeting and Expanding Attack

Malware and tooling: AgendaCrypt, Akira, AnyDesk, Cobalt Strike, DragonForce, G-BOT, LockBit, MimiKatz, SystemBC - S9001, the gentlemen, AnyDesk, Cobalt Strike

How Healthcare Sector Ransomware Targeting and Expanding Attack works

Flare reports healthcare is consistently among the top five most-targeted sectors in an analysis of 1,700+ ransomware attacks over two months, with roughly 80% of observed attacks against US organizations. Qilin, The Gentlemen, Akira, DragonForce and LockBit are the named operators; vendor and government reporting documents their intrusion tradecraft (edge-device exploitation, stolen credentials, remote-management tooling, Cobalt Strike/Rclone, BYOVD, double extortion).

Flare's 2026-10-08 analysis (Assaf Morag) frames healthcare as cybercrime's highest-value target: the FBI IC3 reported 460 ransomware attacks and 182 data breaches against US healthcare in 2025, and healthcare ranked in the top five sectors across 1,700+ ransomware attacks observed over a two-month window, with about 80% of them against US organizations. Protected health information is described as the most expensive PII on the dark web because medical identities cannot be reissued and can be monetized for years. The article cites studies of increased in-hospital mortality during ransomware incidents, and notes ENISA figures that ransomware accounted for 54% (2023) and 45% (2024) of European health-sector incidents. The article itself contains no CVEs, IOCs or new TTPs; technical detail below is drawn from the cross-referenced vendor and government reporting on each named group.

Initial access cited by Flare: phishing, infostealer-harvested staff credentials, browser cookies, session tokens and MFA artifacts, exposed RDP, vulnerable VPN and unpatched edge devices, third-party vendor access, and cloud misconfigurations. Structural weaknesses that amplify impact are legacy and unpatchable Windows/medical systems, flat networks, shared clinical accounts, inconsistent MFA, broad contractor access, incomplete asset inventories and poor IoMT telemetry. Emerging concerns include prompt injection against clinical AI tools, shadow AI, and fraud schemes such as NEMT ghost billing. Flare also references APT29 (COVID-19 vaccine research targeting, 2020), APT40 (China MSS, biomedical/virus-research targeting) and APT10 (healthcare and biotechnology) as nation-state context; these are background and not attributed to the ransomware activity.

Group tradecraft from corroborating sources: CISA's #StopRansomware advisory on Akira (published 2024-04-18, updated 2025-11-13) lists exploitation of Cisco, Veeam, SonicWall, VMware and Windows CVEs, VPNs without MFA, tools such as Mimikatz, Cobalt Strike, AnyDesk, Rclone, WinSCP, Ngrok, AdFind and Impacket, and roughly $244M in proceeds as of late September 2025. The Gentlemen (PRODAFT: Phantom Mantis / LARVA-368; Microsoft: Storm-2697) exploit FortiGate and other edge devices (CVE-2024-55591, CVE-2025-32433, CVE-2025-33073), use NetExec and related AD tooling, EDR-killer/BYOVD tooling, a modified Velociraptor and G-BOT for C2, GPO-based deployment, and a Go locker (X25519 + XChaCha20) with a --spread worm option for Windows, Linux and ESXi. DragonForce is a RaaS cartel (LockBit 3.0/Conti-derived encryptor) using help-desk social engineering, Cobalt Strike, SystemBC, Mimikatz, AdFind, SoftPerfect and Rclone. Qilin (per Security Arsenal reporting) abuses ConnectWise ScreenConnect (CVE-2024-1708), valid credentials from initial access brokers, Cobalt Strike, PsExec and Rclone, exfiltrating before encryption.

MITRE ATT&CK techniques used in TL-2026-3127

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory; T1539 Steal Web Session Cookie

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares

Execution

T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1133 External Remote Services

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing

Command and Control

T1219 Remote Access Tools

Impact

T1490 Inhibit System Recovery; T1657 Financial Theft

Exfiltration

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

defense-impairment

T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Affected products and versions in Healthcare Sector Ransomware Targeting and Expanding Attack

  • Healthcare sector — EHR, imaging, billing, patient portals, telemedicine and IoMT systems
    Vulnerable versions: Legacy/unpatched Windows and unsupported medical software; Flat networks without segmentation
  • Fortinet — FortiGate (CVE-2024-55591)
    Vulnerable versions: Unpatched FortiOS
    Fixed in: Vendor-patched FortiOS
  • ConnectWise — ScreenConnect (CVE-2024-1708)
    Vulnerable versions: Unpatched ScreenConnect
    Fixed in: Vendor-patched ScreenConnect
  • SonicWall / Veeam / Cisco / VMware — VPN, backup and ESXi CVEs listed in CISA Akira advisory
    Vulnerable versions: Unpatched deployments
    Fixed in: Vendor-patched releases

Remediation for Healthcare Sector Ransomware Targeting and Expanding Attack

Patches

  • Apply vendor fixes for CVE-2024-40766 (SonicWall), CVE-2024-40711 (Veeam), CVE-2024-37085 (VMware ESXi), CVE-2023-20269 (Cisco), CVE-2024-55591 (Fortinet), CVE-2024-1708 (ConnectWise ScreenConnect)

Immediate actions

  • Patch internet-facing VPN, firewall, remote-management and mail systems; prioritize CVEs listed in the CISA Akira advisory and CVE-2024-55591, CVE-2024-1708
  • Enforce phishing-resistant MFA on all VPN, RDP, email and remote-access paths and review exposed RDP
  • Hunt for Rclone, WinSCP, AnyDesk, ScreenConnect, Velociraptor and Cobalt Strike activity outside approved use
  • Revoke sessions and reset credentials for staff appearing in infostealer logs

Workarounds

  • Restrict management interfaces to VPN or allow-listed addresses
  • Disable unused remote-access tools and legacy protocols where patching is blocked by vendor certification

Longer-term hardening

  • Segment flat clinical and IoMT networks and monitor east-west traffic
  • Maintain offline, immutable backups of critical data and test restoration
  • Continuously monitor dark-web and stealer-log exposure of staff credentials and PHI
  • Tighten third-party and contractor access and session-token governance
  • Enable EDR tamper protection and block vulnerable signed drivers (BYOVD)

CVEs associated with Healthcare Sector Ransomware Targeting and Expanding Attack

CVE-2024-1708, CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, CVE-2020-3259, CVE-2020-3580, CVE-2023-20269, CVE-2023-28252, CVE-2024-37085, CVE-2023-27532, CVE-2024-40711, CVE-2024-40766

Weaknesses (CWE) in Healthcare Sector Ransomware Targeting and Expanding Attack

CWE-287, CWE-306, CWE-502, CWE-122

Timeline of Healthcare Sector Ransomware Targeting and Expanding Attack

  • CISA, FBI and partners publish the original #StopRansomware advisory on Akira ransomware (AA24-109A).
  • The Gentlemen begin activity as an affiliate-driven double-extortion operation (March 2025), previously using other RaaS programs.
  • First The Gentlemen ransomware sample is uploaded to VirusTotal.
  • CISA and partners update the Akira advisory with new IOCs, TTPs and detection methods; Akira proceeds reported at about $244M as of late September 2025.
  • Internal Rocket.Chat infrastructure of The Gentlemen is leaked following a compromise linked to hosting provider 4VPS (May 2026).
  • Qilin posts about 15 victims in roughly five days (June 2-5, 2026), about 20% in healthcare.
  • The Hacker News reports The Gentlemen have claimed 478 victims and account for about 10% of ransomware activity in April 2026.
  • Barracuda publishes analysis of The Gentlemen, confirming active operations as of 2026-08-14.
  • Flare publishes its analysis of healthcare ransomware targeting across 1,700+ attacks, naming Qilin, The Gentlemen, Akira, DragonForce and LockBit.

Sources cited for Healthcare Sector Ransomware Targeting and Expanding Attack

Detection coverage for TL-2026-3127

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3127 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats