Vice Society Pivots to Inc Ransomware in Healthcare Attack
September 19, 2024 – Published on Dark Reading
Inc ransomware is on the rise, with one well-known threat actor recently using it to target American healthcare organizations.
Vice Society, which Microsoft tracks as Vanilla Tempest, has been active since July 2022. In that time, the Russian-speaking group has made use of various families of ransomware to aid its double extortion attacks, including BlackCat, Hello Kitty, Quantum Locker, Rhysida, Zeppelin — including its own variant — and its own, eponymous program.
In a series of posts on X, Microsoft Threat Intelligence Center (MSTIC) flagged the group’s latest weapon: Inc ransomware.
Active since last summer, the Inc ransomware-as-a-service (RaaS) operation has earned plenty of headlines for its compromises of particularly large organizations — Xerox and Scotland’s National Health Service (NHS), among others. And its modus operandi fits the scope of its ambition, says Jason Baker, threat intelligence consultant for GuidePoint Security.
“The aspect of Inc affiliates in particular that makes them stand out is that they have a very structured way of working through the negotiations process. There’s no winging it. There are no off-the-cuff remarks. Agitation and threats are kept relatively minimal,” he recalls from dealing with them firsthand.
Read More HERE.