In a landmark designation, Mandiant classified a ransomware affiliate as a distinct threat group, the first time it has given an organization of that type a formal name.Ransomware is a complex economy. Ransomware affiliates license the right to install ransomware someone else designed, often purchasing access to pre-breached computers from other actors. The affiliate groups are not tied to a single brand of malware — with many using more than one brand at the same time — and malware is not tied to a single philosophy of who and how to target for installation. But most public discussions around ransomware only focus on the type of ransomware — for example, REvil, Ryuk or LockBit.That oversimplification, said John Hultquist, senior director of analysis at Mandiant, can dramatically limit the conversation on ransomware. Saying Ryuk targets health care is less important than saying an individual affiliate targets health care, because that affiliate might change ransomware brands at any time, or a prolific affiliate might change brands to Ryuk at any time."When we talk about Ryuk ransomware, and are not able to talk about the crew that installs the ransomware, they are able to hide behind the name Ryuk," Hultquist told SC Media. Mandiant announced Thursday that it would track FIN12, a group that tends to install Ryuk and focuses heavily on the health care sector. It is an incredibly prolific actor, responsible for around 20% of Mandiant's ransomware engagements since September 2020.When a Ryuk infection targets health care, it is frequently this group, according to Mandiant's research. At the same time, chatter from ransomware forums shows that other Ryuk actors avoid the healthcare sector on moral grounds. Ryuk does not target health care, Hultquist stressed; specific crews using Ryuk target health care.
Ransomware, Threat Management
Mandiant now tracking prolific ransomware affiliate FIN12 as distinct threat

Emergency Room nurses and EMTs tend to patients in hallways at the Houston Methodist The Woodlands Hospital on August 18, 2021. A ransomware group dubbed by Mandiant as FIN12 tends to install Ryuk and focuses heavily on the health care sector. (Photo by Brandon Bell/Getty Images)
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds