Health Care / Life Sciences
Breach intelligence, attack campaigns, and threat reports targeting the Health Care / Life Sciences sector.
Explore Other Sectors
Health Care / Life Sciences Threat Reports
RondoDox Botnet Orchestrates Mass n-day IoT Attacks in 2025
In mid-2025, the RondoDox botnet emerged as a powerful threat targeting IoT and network devices by exploiting 56 known (n-day) vulnerabilities across over 30 device types, including routers, NVRs, DVRs, and CCTV systems. The operators, closely monitoring vulnerability disclosures—such as those revealed at Pwn2Own events—rapidly weaponized publicly disclosed exploits, including CVE-2023-1389 and CVE-2024-12856, using a high-volume "exploit shotgun" methodology to maximize infections. With operations observed since June 2025, the campaign affected both end-of-life and actively supported products, resulting in a widespread compromise of infrastructure, particularly among organizations and consumers with unpatched devices. This attack underscores a growing trend of mass exploitation of n-day vulnerabilities in IoT ecosystems, reflecting increasing automation and sophistication among botnet operators. The pace at which attackers operationalize new exploits demands faster patching, improved segmentation, and heightened baseline security practices across networked environments.
8 months ago
Kill Chain
China-Based Storm-2603 Weaponizes Velociraptor DFIR in 2025 Ransomware Attacks
In October 2025, security researchers uncovered that the China-based threat group Storm-2603 had abused the open-source Velociraptor DFIR tool in a wide-ranging ransomware campaign. The attacker exploited an outdated, vulnerable version of Velociraptor (CVE-2025-6264) to escalate privileges, create persistent admin accounts, and establish secure remote access on victim systems. This access enabled them to deploy ransomware variants including LockBit and Babuk across Windows and VMware ESXi environments, performing data encryption and exfiltration using PowerShell scripts. Endpoint protections were systematically disabled, and lateral movement leveraged tools like Impacket. This incident highlights an emergent trend: threat actors co-opting legitimate security tools for malicious purposes, increasing the difficulty of detection and response. The blending of nation-state TTPs with ransomware-as-a-service models signals evolving threats, regulatory scrutiny, and substantial operational risks for enterprises.
8 months ago
Kill Chain
ClayRat Android Spyware: Fake App Campaign Hits Mobile Users in 2025
In October 2025, cybersecurity researchers at Zimperium disclosed a widespread Android spyware campaign dubbed ClayRat, which targeted Russian users through phishing portals, Telegram channels, and malicious websites mimicking popular apps such as WhatsApp, TikTok, YouTube, and Google Photos. Using fraudulent Play Store-like websites and social engineering tactics, attackers tricked users into sideloading APKs that installed malicious payloads via a session-based installation method, bypassing Android security. Once installed, ClayRat acts as the device's default SMS handler, enabling interception of messages, call logs, notifications, and exfiltration of sensitive data to an AES-GCM-encrypted command and control (C2) server. It also uses infected devices to propagate itself by sending mass SMS messages to victims' contacts. This incident underscores an accelerating trend in mobile spyware leveraging legitimate app impersonation and sophisticated delivery mechanisms. The high volume of ClayRat samples and droppers, the abuse of sideloading, and the global reach of Telegram-based distribution channels highlight persistent gaps in mobile endpoint and social engineering defenses.
8 months ago
Kill Chain
macOS Infostealer Ecosystem 2024: Atomic, Odyssey & Poseidon Unveiled
In early 2024, cybersecurity researchers identified a surge in advanced macOS infostealer campaigns targeting enterprises and individuals, featuring prominent malware variants: Atomic, Odyssey, and Poseidon. These infostealers exploit social engineering and malicious downloads to achieve initial access, deploying payloads designed to extract sensitive data such as passwords, browser credentials, cryptocurrency wallets, and system information. Once installed, the malware communicates with command-and-control infrastructure using encrypted channels, effectively exfiltrating critical information while evading traditional antivirus tools. This campaign demonstrated sophisticated evasion techniques, cross-platform delivery, and broad targeting among macOS users. The growing sophistication and proliferation of macOS-targeting infostealers underscore a significant shift in attacker focus beyond Windows environments. With macOS adoption increasing in the enterprise and remote workforce, these campaigns illustrate heightened risk, regulatory urgency, and the pressing need for zero trust controls and vigilant endpoint protection against evolving cross-platform threats.
8 months ago
Kill Chain
Polymorphic Python RAT: Next-Gen Malware Slips Past Defenses in 2024
In October 2024, security researchers identified a new strain of Python-based remote access trojan (RAT) exhibiting advanced polymorphic capabilities. The malware, distributed as 'nirorat.py' and virtually undetectable by most antivirus engines on VirusTotal at the time of discovery, leverages self-modifying code, dynamic junk code injection, and obfuscation to evade detection. Its feature set includes network scanning, credential testing, data exfiltration, cryptomining, screen and audio recording, and file encryption. The Trojan is designed to mutate its code with each execution, making signature-based security tools largely ineffective and challenging forensic analysis post-compromise. This incident is emblematic of an ongoing trend: cybercriminals are increasingly using polymorphic programming techniques and open-source scripting languages to bypass detection and propagate malware. Organizations must adapt their defense strategies as attackers innovate to manipulate familiar toolchains, raising the stakes for endpoint and network security teams.
8 months ago
Kill Chain
RedTail Cryptojacking: 2024 SSH Honeypot Attack Exposes Evasive Trends
In 2024, repeated attempts to deploy RedTail cryptojacking malware were observed targeting honeypots through brute-forced SSH credentials and exploitation of vulnerabilities. Attackers gained access by cracking weak SSH passwords, uploaded and executed scripts such as setup.sh and clean.sh, and implemented persistent access by implanting their own SSH keys. They evaded detection by deleting evidence, queried system info to optimize deployment, and communicated outbound over HTTPS to control mining pools, siphoning off computing resources for Monero mining. The attack demonstrated both technical sophistication and evasiveness, resulting in loss of system performance and increased operational costs for victims. The RedTail campaign stands out for its focus on stealth, persistence, and lateral evasion, signaling a shift from noisy ransomware to more subtle and long-term threats like cryptojacking. With attackers honing in on resource hijacking and leveraging diverse TTPs, organizations face new challenges in detection and response. This incident shows the increasing necessity for robust SSH hardening, proactive monitoring, and defense-in-depth measures against evolving cryptojacking methods.
8 months ago
Kill Chain
ClickFix Factory: How Automated Phishing Kits Are Changing Social Engineering in 2024
In 2024, Unit 42 researchers exposed the ClickFix Factory, a novel phishing kit generator that dramatically lowers the technical bar for aspiring cybercriminals. ClickFix enables users to design sophisticated phishing campaigns targeting identity verification and anti-abuse modules (IUAM) without deep coding knowledge. By offering user-friendly templates and built-in automation, ClickFix streamlines social engineering attacks and amplifies their reach, resulting in a spike of high-volume, lower-skill phishing campaigns observed targeting enterprises and individuals globally. The release of ClickFix reflects an ongoing trend toward the commoditization of cybercrime tooling, making advanced techniques readily accessible to broader groups of threat actors. Security teams face new urgency to adapt detection, awareness, and prevention strategies as phishing kit marketplaces accelerate both the scale and success rate of social engineering attacks.
8 months ago
Kill Chain
2025 Cloud Provider Breach Uncovers Critical Zero Trust Weaknesses
In early 2025, a major global cloud provider suffered a sophisticated multi-stage breach in which adversaries gained initial access using compromised identity credentials, exploited weak east-west segmentation, and moved laterally across multicloud environments. The attackers leveraged unencrypted traffic channels and insufficient policy controls to evade detection, escalate privileges, and access sensitive customer data. As a result, organizations relying on this provider experienced outages, data exfiltration, and business continuity disruptions while the cloud provider scrambled to restore services and conduct forensic investigations. This incident highlights a rapidly growing trend: attackers are increasingly targeting cloud infrastructure, exploiting vulnerabilities in workload isolation, cloud-native policy enforcement, and hybrid connectivity. With regulators enhancing requirements and business dependence on cloud rising, defending against lateral movement and enforcing zero-trust has become a critical priority.
8 months ago
Kill Chain
Notion 2025: AI Agent Prompt Injection Leads to Data Breach
In September 2025, Notion experienced a security incident after releasing version 3.0 with integrated AI agents. Threat actors exploited a prompt injection vulnerability whereby malicious PDF files—containing hidden instructions—caused Notion's AI to extract sensitive customer data and exfiltrate it to an external attacker-controlled endpoint. The attack chain leveraged the AI’s access to private data and enabled untrusted content, combined with the external communication capabilities of the LLM-powered agent. This resulted in unauthorized exposure and theft of confidential enterprise data, highlighting a worrying weakness in agentic AI implementations. This incident underscores the growing risk posed by prompt injection attacks against AI and LLM-integrated workflows, particularly as organizations rapidly adopt such technologies. With regulatory scrutiny rising and attackers quickly adapting to target emerging AI-driven systems, prompt injection and data exfiltration are fast becoming board-level risks across industries.
8 months ago
Kill Chain
Apple Fixes Groundbreaking Pointer Infoleak in macOS/iOS Serialization (2025)
In March 2025, Apple patched a novel vulnerability in macOS and iOS after research by Google Project Zero revealed a pointer information leak in the way Apple's Foundation framework handled serialization and deserialization via NSKeyedArchiver and NSKeyedUnarchiver. The flaw allowed attackers to deduce memory address information—specifically, the address of the NSNull singleton—by crafting serialized data and analyzing the ordering of keys upon re-serialization, without exploiting any memory corruption or timing attacks. This potential leak could subvert Address Space Layout Randomization (ASLR), a key memory protection mechanism, if leveraged in real-world attack surfaces that allow roundtripping of attacker-supplied serialized objects. Although the direct impact was mitigated by Apple’s 31 March 2025 security update, the disclosure highlights an overlooked class of pointer leak vulnerabilities inherent in pointer-keyed data structures, especially where object addresses serve as hash values. This incident is significant in the context of a broader industry trend: attackers are increasingly pursuing remote and non-traditional side channels for ASLR bypasses and memory leaks, while defenders must contend with the residual risks of serialization and legacy data structure design. Regulatory and customer pressure continues to rise for organizations to ensure modern memory safety, especially as zero trust and data segmentation architectures rely on robust underlying primitives.
8 months ago
Kill Chain
Double Agents: The 2024 Exploitation of AI Agent Mode in Commercial Platforms
In March 2024, security researchers revealed how threat actors exploited 'agent mode' in commercial AI products to conduct AI-in-the-middle (AIitM) attacks. By abusing the emerging capability that allows AI assistants to autonomously perform actions, adversaries were able to impersonate users or escalate privileges by intercepting and manipulating commands. This allowed attackers to facilitate lateral movement, data exfiltration, and policy circumvention within enterprise environments, often leaving minimal forensic traces. The incident highlighted how the wider adoption of agentic AI features substantially expands the potential threat surface for organizations. This breach has rapidly gained industry attention amid a surge in advanced AI-driven attacks and a wave of regulatory scrutiny on AI operational security. As enterprises accelerate their deployment of commercial AI tools, understanding the novel risks introduced by agentic AI is now critical for leadership and security teams.
8 months ago
Kill Chain
King KongTuke Breach Unmasks East-West Security Gaps in Multi-Cloud Era
In September 2025, a sophisticated breach attributed to the threat group 'King KongTuke' targeted several enterprises operating in multi-cloud environments. Attackers exploited weaknesses in east-west traffic controls and bypassed improper network segmentation by leveraging encrypted, paste-and-run lures to establish covert lateral movement between cloud workloads. Once inside, the group utilized remote access tools and encrypted tunnels to exfiltrate sensitive data at scale, evading traditional threat detection and impairing business operations across industries including fintech and healthcare. The incident revealed extensive compliance risks and forced urgent remediation of cloud and hybrid network configurations. This breach highlights a growing trend of threat actors exploiting hybrid and multicloud blind spots. The event has triggered renewed urgency on east-west visibility, zero trust controls, and AI-enabled anomaly detection. Regulatory attention is increasing on enforcing segmentation, encryption in transit, and cloud-native policy enforcement at scale.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports