✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
TA558 Leverages AI-Generated Scripts to Deploy Venom RAT in 2025 Brazilian Hotel Attacks
In the summer of 2025, the threat actor group TA558 launched a series of targeted phishing campaigns against hotels and the hospitality sector in Brazil and other Spanish-speaking regions. Leveraging AI-generated scripts, TA558 distributed Remote Access Trojans (RAT) such as Venom RAT via malicious email attachments disguised as business invoices. The attackers gained unauthorized access to hotel infrastructure, enabling surveillance, data theft, and lateral movement within targeted environments. Kaspersky researchers attributed the activity to the RevengeHotels cluster and noted reliance on sophisticated social engineering and automation. This incident exemplifies the rising integration of AI in cyberattacks, increasing the efficacy and resilience of threat actors like TA558. Organizations in hospitality and other sectors with valuable customer data face growing risks from AI-driven malware and must adapt their defenses to faster-evolving adversarial techniques.
6 months ago
Kill Chain
ChillyHell: The macOS Backdoor That Outsmarted Notarization in 2024
In early May 2024, security researchers from Jamf Threat Labs identified a new version of the previously dormant "ChillyHell" modular backdoor targeting macOS systems. Initially observed in attacks against Ukrainian officials in 2021 and reported again by Mandiant in 2023, ChillyHell resurfaced in a sample uploaded to VirusTotal and discovered to have been publicly hosted on Dropbox. The malware achieves persistence through multiple mechanisms, brute-forces passwords, exfiltrates sensitive data, and communicates over several protocols, all while leveraging Apple notarization to evade detection before its certificates were revoked. With built-in timestamp manipulation and extensive C2 capabilities, ChillyHell poses a significant risk to macOS enterprise environments, blending stealth, flexibility, and longevity in its operations. This incident underscores the growing sophistication and targeting of macOS platforms by advanced threat actors, moving beyond Windows-centric malware trends. The use of valid codesigning and notarization further demonstrates challenges for defenders, highlighting the need for robust detection controls and ongoing vigilance for notarized—but malicious—macOS software.
6 months ago
Kill Chain
AI-Enhanced Malware: How EvilAI’s Stealth Attacks Redefined Cyber Threats in 2024
In early 2024, cybersecurity researchers identified a widespread campaign leveraging 'EvilAI'—a threat actor embedding artificial intelligence into seemingly legitimate productivity apps to deliver advanced malware. These AI-backed tools enable the malware to evade traditional antivirus detection, utilizing encrypted traffic and adaptive, stealthy behavior to propagate across organizational networks. The primary attack vectors were phishing emails and malicious downloads, which provided initial access before lateral movement was observed within compromised environments. As a result, hundreds of companies worldwide suffered business disruptions, data theft, and increased recovery costs from incident response efforts. This incident highlights the escalating sophistication of malware campaigns driven by artificial intelligence. The fusion of classic malware tactics with AI-enabled evasion makes traditional security controls less effective, underlining the urgency for organizations to adopt advanced, behavior-based defenses and prioritize zero trust architectures to mitigate evolving threats.
6 months ago
Kill Chain
CERT-FR Uncovers Advanced Apple Spyware Exploitation in 2024
In June 2024, a CERT-FR advisory revealed the exploitation of a zero-day vulnerability within Apple operating systems, alleged to be leveraged in targeted spyware attacks against select individuals. Discovered after reports of 'sophisticated' exploitation, the flaw allowed attackers to covertly gain access to devices, harvest sensitive data, and monitor communications by bypassing security defenses. Attackers deployed advanced tactics to deliver the payload, focusing on high-profile victims with a history of surveillance targeting. Apple has since released security updates to address the vulnerability, but the impact underscores persistent risks to user privacy and national security. This incident is particularly relevant amid a surge in zero-day exploitation by sophisticated threat actors, highlighting the elevated risks posed by commercial spyware and surveillance tools. It also reinforces regulatory and enterprise urgency to enhance detection, patch management, and mobile endpoint security strategies.
6 months ago
Kill Chain
FBI Alert: UNC6040 & UNC6395 Target Salesforce Customers with Cloud Attacks (2024)
In early 2024, the FBI’s Internet Crime Complaint Center (IC3) issued an alert detailing active campaigns by threat groups UNC6040 and UNC6395 targeting Salesforce customer environments. The attackers leveraged phishing and social engineering to obtain valid Salesforce credentials, subsequently exploiting misconfigurations and inadequate security controls in customer cloud instances. This enabled unauthorized access to sensitive data, including customer information and corporate records, leading to multiple data theft and extortion attempts. Salesforce itself was not breached, but its customers suffered direct operational impacts due to data compromise and disruption. This incident underscores a rising trend of advanced threat actors targeting supply chain and SaaS ecosystems, exploiting both human and technical gaps in cloud security. As cloud adoption accelerates, enterprises must address credential hygiene, proper configuration, and real-time anomaly detection to thwart similar attacks.
6 months ago
Kill Chain
KillSec Ransomware Campaign Targets Brazilian Healthcare Supply Chain
In April 2024, the KillSec ransomware group orchestrated a cyberattack against a major Brazilian healthcare software provider, targeting a core element of the nation’s healthcare technology supply chain. According to cybersecurity researchers, the attackers leveraged sophisticated ransomware tactics to breach the provider’s environment, exfiltrate sensitive patient data, and subsequently encrypt vital systems, disrupting normal operations. The breach involved the theft of confidential healthcare records, potentially exposing personally identifiable information (PII) as well as critical medical data, raising alarms across Brazil’s healthcare sector. As a result, provider services experienced significant operational delays and financial impact, and the wider ecosystem faces cascading risks from the exposed data. This incident is particularly noteworthy due to the healthcare sector’s growing vulnerability to ransomware attacks, with supply chain vectors increasingly exploited by threat actors like KillSec. The event reflects a concerning trend of ransomware groups shifting toward critical infrastructure and service-provider targets, amplifying regulatory, compliance, and patient safety pressures.
6 months ago
Kill Chain
HybridPetya Ransomware: How Attackers Bypassed Secure Boot to Compromise UEFI
In June 2024, cybersecurity researchers uncovered a new ransomware strain called 'HybridPetya' that combines elements of the notorious Petya and NotPetya malware families. This advanced ransomware specifically targets UEFI-based systems, bypassing Secure Boot protections by leveraging sophisticated bootkit techniques. HybridPetya infiltrates environments via spear-phishing and lateral movement, then encrypts critical system files at the firmware level, effectively crippling affected organizations and creating significant hurdles for recovery. Its wiper-like capabilities echo NotPetya’s destructive impacts, raising major concerns for enterprises with critical infrastructure or legacy firmware defenses. The emergence of HybridPetya underscores an escalation in attacker sophistication, with a resurgence in supply-chain and firmware-level attacks. The incident highlights the urgent need for proactive firmware security, robust patch management, and Zero Trust architectures to counter ransomware operators increasingly weaponizing advanced, persistent threat techniques.
6 months ago
Kill Chain
Emerging Yurei Ransomware Claims First Victims in 2024
In early June 2024, a new ransomware operation identified as Yurei, reportedly originating from Morocco and named after Japanese spirits, claimed its first set of confirmed victims. The Yurei group leveraged a customized variant of the Prince-Ransomware binary, successfully breaching targets by deploying file-encrypting malware through typical ransomware vectors. Notably, researchers discovered that the malware implementation contained a technical flaw permitting partial data recovery, though this did not nullify the criminal extortion threats made against affected businesses. The attack has led to data loss, service interruption, and urgent incident response at affected organizations. This incident spotlights the evolving ransomware landscape, where new actors rapidly weaponize existing malware tools, often introducing subtle encryption modifications. Yurei’s activity shows how flaws in ransomware code do not necessarily mitigate risk, as extortion and operational disruption remain impactful. Organizations must adapt controls to defend against agile threat actors, even when exploits are imperfectly engineered.
6 months ago
Kill Chain
The FileFix Phishing Campaign: Obfuscation, Steganography, and Multilingual Threats Hit Globally
In early 2024, security researchers identified a sophisticated, widescale phishing campaign leveraging a malicious tool called FileFix. The campaign utilized advanced code obfuscation, steganography, and localization in at least 16 languages to distribute phishing payloads globally. Attackers delivered FileFix through deceptive emails and malicious attachments, successfully bypassing traditional security filters. Once executed, the malware embedded within attachments enabled remote access, data theft, and credential harvesting, affecting organizations in multiple sectors and exposing sensitive business data to potential fraud and operational disruption. FileFix highlights a new wave of phishing threats combining obfuscation, multilingual lures, and novel payload delivery. Its rapid evolution and global reach underscore the increasing sophistication of social engineering attacks, making robust detection and segmentation capabilities essential for all enterprises.
6 months ago
Kill Chain
Salty2FA: The Next Wave of Enterprise Phishing-as-a-Service in 2024
In early 2024, cybersecurity researchers uncovered the Salty2FA Phishing-as-a-Service (PhaaS) kit, designed to bypass multi-factor authentication (MFA) protections for enterprise environments. The kit enables attackers to launch highly convincing phishing campaigns by emulating trusted authentication flows and harvesting credentials—including two-factor tokens—using adversary-in-the-middle proxy techniques. Salty2FA's modular architecture, scalability, and integration with encrypted communication channels make it particularly appealing to cybercriminals targeting corporate user bases. Compromised accounts can facilitate credential stuffing, lateral movement, and data exfiltration in victim organizations. This incident highlights the growing professionalization of cybercriminal groups and a trend toward sophisticated PhaaS offerings that significantly lower barriers for conducting enterprise-level breaches. Organizations should note the surge in attacks able to circumvent standard MFA and adapt their defenses accordingly.
6 months ago
Kill Chain
Raven Stealer Uses Telegram to Pilfer Chromium Data in 2024
In early 2024, security researchers identified a new infostealer variant, Raven Stealer, being distributed via underground forums and cracked software packages. The malware targets Windows systems and focuses on stealthy extraction of browser data, particularly from Chromium-based browsers such as Google Chrome. Once installed, Raven Stealer harvests credentials, cookies, browser histories, and cryptocurrency wallets before exfiltrating the data through encrypted Telegram channels. The attack exploits unmonitored endpoints and capitalizes on users’ download of pirated or repackaged software, resulting in widespread compromise of sensitive authentication data across multiple organizations. This incident underscores the ongoing evolution of commodity malware and demonstrates the sophistication with which even low-cost infostealers are leveraging encrypted communications and social engineering. As attackers continue to innovate with new TTPs and delivery vectors, organizations must strengthen endpoint monitoring and policy enforcement to reduce exposure to similar threats.
6 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Critical Privilege Escalation Flaws Demand Immediate Action
In September 2025, Microsoft disclosed 81 security vulnerabilities across its portfolio, with a significant focus on escalation of privilege (EoP) flaws. Of the CVEs released, 38 enabled attackers to gain elevated access after initial compromise, affecting modules like SMB and NTLM. Notably, CVE-2025-55234 (SMB) and CVE-2025-54918 (NTLM)—both rated CVSS 8.8—were publicly known and considered high impact, allowing attackers to leverage relay and crafted packet attacks for system takeover. Additional critical vulnerabilities were identified in Windows UI XAML and HPC components. While no active exploitation was confirmed at release, the breadth of affected products and criticality prompted urgent patching recommendations. This wave of privilege escalation vulnerabilities underscores the ongoing risk posed by identity-based attacks and lateral movement, compelling organizations to accelerate patch deployment and strengthen segmentation controls. With the end-of-life of Windows 10 and expanded MFA mandates on the horizon, the incident reinforces the necessity for layered defenses and up-to-date asset management.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports