14-09-2026
RDP-based Beast (GodDamn) ransomware attack targeting domestic medical institutions
https://alyacofficialblog.tistory.com/5779
Report completeness: High
Threats:
Goddamn_ransomware
Smishing_technique
Process_hacker_tool
Pchunter_tool
Beast_ransomware
Shadow_copies_delete_technique
Victims:
Healthcare institutions
Industry:
Healthcare, Financial
Geo:
Russian
TTPs:
Tactics: 2
Technics: 0
ChatGPT TTPs:
do not use without manual checkT1021.001, T1027, T1047, T1070.004, T1105, T1135, T1140, T1480, T1486, T1489, have more...
IOCs:
File: 40
Path: 1
Registry: 1
Hash: 2
Soft:
chrome, MySQL, Outlook, onenote, wordpad, thebat, firefox, kingdee, steam, MSSQL, have more...
Algorithms:
md5, chacha20
Win API:
TerminateProcess, Boot, Microsoft
Win Services:
ocssd, dbsnmp, isqlplussvc, ocautoupds, xfssvccon, sqlservr, sqlagent, sqlbrowser, sqlwriter, dbeng50, have more...
Languages:
python
Platforms:
intel