Microsoft has disclosed that a financially motivated threat group, Vanilla Tempest, has begun using a ransomware strain called INC to target the healthcare sector in the U.S. The tech giant's threat intelligence team has been tracking this group, previously known as DEV-0832, under its new name.
"Vanilla Tempest receives hand-offs from GootLoader infections initiated by the threat actor Storm-0494, before deploying tools like the Supper backdoor, the legitimate AnyDesk remote monitoring and management (RMM) tool, and the MEGA data synchronization tool," Microsoft explained in a series of posts shared on X.
Once these initial infections are in place, the attackers use Remote Desktop Protocol (RDP) for lateral movement and the Windows Management Instrumentation (WMI) Provider Host to deploy the INC ransomware payload.
Vanilla Tempest has been active since at least July 2022, primarily targeting the education, healthcare, IT, and manufacturing sectors. They have previously used ransomware strains such as BlackCat, Quantum Locker, Zeppelin, and Rhysida. The group, also tracked under the alias Vice Society, is notorious for using pre-existing ransomware lockers rather than developing their own.
In recent developments, ransomware groups like BianLian and Rhysida have adopted Azure Storage Explorer and AzCopy tools to exfiltrate data from compromised networks, evading detection. These tools, traditionally used for managing Azure storage, are now repurposed by attackers for large-scale data transfers to cloud storage.
"This tool, used for managing Azure storage and objects within it, is being repurposed by threat actors for large-scale data transfers to cloud storage," Britton Manahan, a modePUSH researcher, said.