Hospitals and health systems are squarely in the path of a ransomware campaign that U.S. agencies and allied partners flagged in a joint advisory this week. The FBI, CISA, the U.S. Secret Service, and South Korea’s National Police Agency co-signed the alert, which counts healthcare, finance, manufacturing, transportation, utilities, and academia among the affected sectors.
The operation first surfaced in April 2025 as a financially motivated actor and, by January 2026, had restructured into a ransomware-as-a-service business, posting recruitment pitches on dark web forums. Victims have appeared across the Americas, Europe, the Middle East, Africa, and Asia-Pacific, and the tempo of attacks has climbed through 2026. New affiliates receive a management console, a configurable locker builder, and full documentation.
The encryptor derives from leaked Conti source code and is built for Windows first, with a Linux variant following in late 2025. Operators practice double extortion, siphoning data out of the network before any files are locked, and their playbook leans on stealth to stay ahead of detection.
A ransom note appears in every affected folder and points victims to a Tor-hosted negotiation portal, where each receives a Client ID and temporary password and gets five to ten days to open talks, with follow-up via the encrypted messenger qTox. Affiliates keep 80% of any payment, a split designed to attract seasoned operators and the access brokers who sell entry points into corporate networks. The group typically breaks in through known flaws in internet-facing appliances, including the FortiOS and FortiProxy authentication bypasses cataloged as CVE-2024-55591 and CVE-2025-24472 and SSH access-control weaknesses in VPN gateways, making patching of VPN and RDP-facing systems the advisory’s top recommendation.
