Daixin Team is a cybercriminal group known for ransomware attacks on the healthcare sector.
Analyst brief
Daixin Team is a threat actor group active since at least June 2022, primarily targeting the healthcare and public health sectors with ransomware attacks. They also hit aerospace, automotive, and packaged foods industries, using VPN server exploits, phishing, or credential theft for initial access. Key TTPs involve data exfiltration and extortion for ransom. Defenders should focus on securing VPNs with MFA, monitoring for lateral movement, and strengthening anti-phishing measures.
Daixin Team
unknown
Daixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware attacks, stealing sensitive data and threatening to release it if a ransom is not paid. They have successfully targeted various industries, including healthcare, aerospace, automotive, and packaged foods. Daixin gains initial access through VPN servers and exploits vulnerabilities or uses phishing attacks to obtain credentials. They have been responsible for cyberattacks on organizations such as the North Texas Municipal Water District and TransForm Shared Service Org, impacting their networks and stealing customer and patient information.