Motivation: Financial
Steals files (patient records, drivers licenses, tax forms) and threatens exposure rather than encrypting, emerging October 2025 with over half its early victims being US healthcare organizations. Uses credential-based access and abuses legitimate infrastructure for lateral movement, targeting lower-maturity SMB healthcare; may also broker stolen data. Distinct from the older INSOMNIA mobile malware (MITRE S0463).
Optimized for stealthy exfiltration over disruptive encryption; uses credential-based access (incl. infostealer-sourced creds and auth-bypass flaws) and abuses legitimate infrastructure for lateral movement. Targets lower-security-maturity SMB healthcare (~$5-57M revenue). May also act as a broker/platform for stolen data. Note: distinct from the older INSOMNIA mobile malware (MITRE S0463).
Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →
Check your exposure privately, or request a tailored exposure audit.