Insomnia

Insomnia — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

InsomniaConfidence: Medium

Data theft / extortion
Also known as: INSOMNIA

Motivation: Financial

3Attributed Breaches Circulating
MediumAttribution Confidence
Data theft / extortionActor Type

Overview

Steals files (patient records, drivers licenses, tax forms) and threatens exposure rather than encrypting, emerging October 2025 with over half its early victims being US healthcare organizations. Uses credential-based access and abuses legitimate infrastructure for lateral movement, targeting lower-maturity SMB healthcare; may also broker stolen data. Distinct from the older INSOMNIA mobile malware (MITRE S0463).

Tactics, Targeting & TTPs

Optimized for stealthy exfiltration over disruptive encryption; uses credential-based access (incl. infostealer-sourced creds and auth-bypass flaws) and abuses legitimate infrastructure for lateral movement. Targets lower-security-maturity SMB healthcare (~$5-57M revenue). May also act as a broker/platform for stolen data. Note: distinct from the older INSOMNIA mobile malware (MITRE S0463).

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation