# Healthcare Sector Ransomware Targeting and Expanding Attack Surface (Qilin, Akira, DragonForce, LockBit, The Gentlemen)

> Flare reports healthcare is consistently among the top five most-targeted sectors in an analysis of 1,700+ ransomware attacks over two months, with roughly 80% of observed attacks against US organizations. Qilin, The Gentlemen, Akira, DragonForce and LockBit are the named operators; vendor and government reporting documents their intrusion tradecraft (edge-device exploitation, stolen credentials, remote-management tooling, Cobalt Strike/Rclone, BYOVD, double extortion).

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3127
- **ID:** TL-2026-3127
- **Severity:** HIGH
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Qilin
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2024-1708, CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, CVE-2020-3259, CVE-2020-3580, CVE-2023-20269, CVE-2023-28252, CVE-2024-37085, CVE-2023-27532, CVE-2024-40711, CVE-2024-40766, CVE-2024-1709

## Description

Flare's 2026-10-08 analysis (Assaf Morag) frames healthcare as cybercrime's highest-value target: the FBI IC3 reported 460 ransomware attacks and 182 data breaches against US healthcare in 2025, and healthcare ranked in the top five sectors across 1,700+ ransomware attacks observed over a two-month window, with about 80% of them against US organizations. Protected health information is described as the most expensive PII on the dark web because medical identities cannot be reissued and can be monetized for years. The article cites studies of increased in-hospital mortality during ransomware incidents, and notes ENISA figures that ransomware accounted for 54% (2023) and 45% (2024) of European health-sector incidents. The article itself contains no CVEs, IOCs or new TTPs; technical detail below is drawn from the cross-referenced vendor and government reporting on each named group.

Initial access cited by Flare: phishing, infostealer-harvested staff credentials, browser cookies, session tokens and MFA artifacts, exposed RDP, vulnerable VPN and unpatched edge devices, third-party vendor access, and cloud misconfigurations. Structural weaknesses that amplify impact are legacy and unpatchable Windows/medical systems, flat networks, shared clinical accounts, inconsistent MFA, broad contractor access, incomplete asset inventories and poor IoMT telemetry. Emerging concerns include prompt injection against clinical AI tools, shadow AI, and fraud schemes such as NEMT ghost billing. Flare also references APT29 (COVID-19 vaccine research targeting, 2020), APT40 (China MSS, biomedical/virus-research targeting) and APT10 (healthcare and biotechnology) as nation-state context; these are background and not attributed to the ransomware activity.

Group tradecraft from corroborating sources: CISA's #StopRansomware advisory on Akira (published 2024-04-18, updated 2025-11-13) lists exploitation of Cisco, Veeam, SonicWall, VMware and Windows CVEs, VPNs without MFA, tools such as Mimikatz, Cobalt Strike, AnyDesk, Rclone, WinSCP, Ngrok, AdFind and Impacket, and roughly $244M in proceeds as of late September 2025. The Gentlemen (PRODAFT: Phantom Mantis / LARVA-368; Microsoft: Storm-2697) exploit FortiGate and other edge devices (CVE-2024-55591, CVE-2025-32433, CVE-2025-33073), use NetExec and related AD tooling, EDR-killer/BYOVD tooling, a modified Velociraptor and G-BOT for C2, GPO-based deployment, and a Go locker (X25519 + XChaCha20) with a --spread worm option for Windows, Linux and ESXi. DragonForce is a RaaS cartel (LockBit 3.0/Conti-derived encryptor) using help-desk social engineering, Cobalt Strike, SystemBC, Mimikatz, AdFind, SoftPerfect and Rclone. Qilin (per Security Arsenal reporting) abuses ConnectWise ScreenConnect (CVE-2024-1708), valid credentials from initial access brokers, Cobalt Strike, PsExec and Rclone, exfiltrating before encryption.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1566 Phishing
- T1199 Trusted Relationship
- T1133 External Remote Services
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1047 Windows Management Instrumentation
- T1685 Disable or Modify Tools
- T1685.005 Clear Windows Event Logs
- T1003.001 OS Credential Dumping: LSASS Memory
- T1539 Steal Web Session Cookie
- T1021.001 Remote Services: Remote Desktop Protocol
- T1021.002 Remote Services: SMB/Windows Admin Shares
- T1219 Remote Access Tools
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
- T1490 Inhibit System Recovery
- T1657 Financial Theft

## Sources

- [Healthcare Is Cybercrime's Highest-Value Target: Ransomware, Exposure, and the Expanding Attack Surface (Flare)](https://flare.io/learn/resources/blog/healthcare-ransomware-attack-surface)
- [CISA #StopRansomware: Akira Ransomware (AA24-109A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a)
- [CISA and Partners Release Advisory Update on Akira Ransomware](https://content.govdelivery.com/accounts/USDHSCISA/bulletins/3fb462a)
- [The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm (The Hacker News)](https://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html)
- [The Gentlemen ransomware: Inside one of the fastest-growing extortion operations (Barracuda)](https://blog.barracuda.com/2026/08/17/the-gentlemen-ransomware--inside-one-of-the-fastest-growing-rans)
- [DragonForce Ransomware attacks on retail giants (Picus Security)](https://picussecurity.com/resource/blog/dragonforce-ransomware-attacks-retail-giants)
- [Threat Intelligence Report: DragonForce (Centre for Cybersecurity Belgium)](https://ccb.belgium.be/news/threat-intelligence-report-dragonforce)
- [Qilin Ransomware global surge in healthcare and energy sectors (Security Arsenal)](https://securityarsenal.com/blog/qilin-ransomware-global-surge-in-healthcare-and-energy-sectors-campaign-analysis-and-detection-engineering)
- [Agencies warn healthcare sector to bolster defenses against Akira ransomware (This Week Health)](https://thisweekhealth.com/news/agencies-warn-healthcare-sector-bolster-defenses-against-akira-ransomware/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3127
