Healthcare and Public Health sector
69 groups observed targeting this sector
The Healthcare and Public Health sector is targeted by nation-state (APT42, Turla, WIZARD SPIDER, Tortoiseshell, Molerats, APT18, POLONIUM, APT41, BANISHED KITTEN) and crime-oriented (incransom, play, anubis, aurora, Barracuda, Black X, blacknevas, bravox) actors.
Groups targeting you25
- APT42nation-stateIran
- Earth LuscaunknownChina
- incransomcrime
- playcrime
- ShinyHuntersunknown
- TA505unknownRussia
- Turlanation-stateRussia
- WIZARD SPIDERnation-stateRussia
- Storm-1567unknown
- Tortoiseshellnation-stateIran
- Moleratsnation-statePalestine
- APT18nation-stateChina
- WOLF SPIDERunknownRO
- POLONIUMnation-stateLebanon
- APT41nation-stateChina
- anubiscrime
- APT9unknownChina
- auroracrime
- BANISHED KITTENnation-stateIran
- Barracudacrime
- Black Xcrime
- blacknevascrime
- Booba Projectunknown
- BrainCiphercrime
- bravoxcrime
Most-used techniques25
The most-used TTPs include Ingress Tool Transfer (T1105), Valid Accounts (T1078), Spearphishing Attachment (T1566.001), and Exfiltration to Cloud Storage (T1567.002). These techniques enable actors to gain access to systems, steal data, and establish C2 communication.
- T1105Ingress Tool Transfer
- T1588.002Tool
- T1078Valid Accounts
- T1036.005Match Legitimate Resource Name or Location
- T1059.003Windows Command Shell
- T1059.005Visual Basic
- T1112Modify Registry
- T1560.001Archive via Utility
- T1566.001Spearphishing Attachment
- T1567.002Exfiltration to Cloud Storage
- T1018Remote System Discovery
- T1021.002SMB/Windows Admin Shares
- T1059.001PowerShell
- T1082System Information Discovery
- T1133External Remote Services
- T1189Drive-by Compromise
- T1190Exploit Public-Facing Application
- T1204.002Malicious File
- T1547.001Registry Run Keys / Startup Folder
- T1566.002Spearphishing Link
- T1583.001Domains
- T1657Financial Theft
- T1685Disable or Modify Tools
- T1003.001LSASS Memory
- T1005Data from Local System
Defense5
- 01
Implementing EDR solutions to detect illegitimate activities in networks and systems
- 02
Preventing Valid Accounts (T1078) technique by implementing MFA
- 03
Enhancing security awareness and training users against Spearphishing Attachment (T1566.001) attacks
- 04
Monitoring and controlling network traffic to prevent Ingress Tool Transfer (T1105) and Exfiltration to Cloud Storage (T1567.002) techniques
- 05
Regularly updating systems and software to prevent T1190 Exploit Public-Facing Application technique
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources โ not a substitute for a tailored risk assessment.