The “FIN12” threat group has been attracting attention for deploying ransomware in a quarter of the time typically needed, making it one of the fastest ransomware groups active today. Unlike other groups, FIN12 has not fully embraced the double-extortion technique, relying mainly on encryption. This approach enables the group to focus on improving attack efficiency, and to avoid problems with managing data-leak websites. FIN12 has primarily targeted the healthcare sector; the elevated risk posed by blocking access to healthcare systems likely explains the group’s success in receiving ransom payments. Such attacks have allegedly resulted in deaths. Regardless of the consequences, FIN12 is expected to wage more attacks, and probably become more efficient and destructive.

×
Want these
Threat Intelligence reports sent straight to your inbox?
Subscribe below!
Thank you!
Error - something went wrong!
Most Recent Flipbooks
Weekly Intelligence Summary 21 October
Main story: Ransom Cartel and REvil: Partners in cybercrime?
Weekly Intelligence Summary 14 Oct
Main story: Hacktivists fan flames of Iranian anti-regime protests
Weekly Intelligence Summary 07 Oct
Main story: ProxyNotShell spells déjà vu for MS Exchange Server defenders
Weekly Intelligence Summary 30 Sept
Main story: Rogue ex-developer leaks LockBit 3.0 builder
Weekly Intelligence Summary 23 Sept
Main story: Uber compromised by Lapsus$'s resurgence
Weekly Intelligence Summary 16 Sept
Main story: Cyber attacks shock the Italian energy sector
Weekly Intelligence Summary 09 Sept
Main story: Back to school for students and ransomware groups