The Department of Health and Human Services Health Sector Cybersecurity Coordination Center (HC3) this week released an advisory about Everest, a ransomware-as-a-service group increasingly targeting the health care field. The group is known to access systems through compromised user accounts and common remote access tools.

“Yet another Russian-speaking ransomware group targets U.S. health care,” said John Riggi, AHA national advisor for cybersecurity and risk. “Everest appears to have morphed into what is known as an ‘initial access broker’ meaning their role in the underground Russian ransomware economy is to facilitate ransomware attacks by initially gaining unauthorized access to a victim organization through such means as credential theft. They then sell the unauthorized access to other gangs, who conduct the ransomware attack. It is noted that Everest, like other gangs, utilizes legitimate cybersecurity threat simulation tools such as Cobalt Strike to facilitate their attacks. It is recommended that health care organizations set network monitoring tools to alert for Cobalt Strike activations, implement the recommended mitigations included in the alert, and implement the voluntary health care cybersecurity performance goals.”

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity

Headline
The House Energy and Commerce Subcommittee on Health held a hearing Sept. 15 to discuss more than a dozen legislative proposals regarding Medicare provider…
Headline
The National Security Agency has released a best practices guide on effective cyber hygiene for defending against advanced cyber threats, including those…
Headline
An FBI alert released Sept. 1 warns of cyber actors impersonating government officials, media and other public individuals on a commercial messaging app to…
Headline
In this conversation, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, break…
Headline
Boston Scientific announced Sept. 8 that the network disruption to its remote monitoring services following an Aug. 25 cyber incident has been resolved. The…
Headline
The FBI and the Department of Justice Aug. 26 announced the disruption of a China-linked hacking group known as QTFY. The group, which also identifies as QT…