Malware

Alabama Hospitals Resume Operations After Paying Ransom Payment

Alabama hospitals chain resume operations after ransomware paying ransom payment. The operations are back to normal 10 days and the hospitals start treating people.

Ten hospitals, three in Alabama and seven in Australia are frozen with a ransomware attack, and the operations are down for more than 10 days.

“A criminal is limiting our ability to use our computer systems in exchange for an as-yet-unknown payment,” DCH representatives wrote in a release. “Our hospitals have implemented our emergency procedures to ensure safe and efficient operations in the event technology dependent on computers is not available.”

Hospitals isolated the affected machine to stop the flow of attack and the hospital spokesperson said no patient records were accessed.

According to the Apnews report, the hospitals in the west Alabama cities of Tuscaloosa, Northport, and Fayette started admitting patients.

The hospital said that attackers frozen the hospital’s computer systems using Ryuk ransomware, all the files have been encrypted.

The company didn’t reveal how much ransom amount was paid to regain access to the systems, according to hospital spokesperson the insurance covered the ransom payment. Generally, the Ryuk ransomware payment varies among the victims ranging between 15 BTC to 50 BTC.

Ryuk ransomware also known as targeted ransomware, this ransomware will not be distributed through mass spam campaigns, they are used exclusively in targeted attacks.

Once the encryption completed it creates a file named RyukReadMe.txt, which shows the contact email address and BTC address for payment.

Ryuk Ransomware

The ransomware gain’s its popularity at the end of December 2018, it targets victims of different industries including logistics, technology companies, healthcare as well as small municipalities.

It is capable of stealing information and to encrypt files on the disk. the threat actors behind Ryuk ransomware combine multiple advanced attack techniques to penetrate the network.

Also Read

Exploiting an Exim Email Server Vulnerability Using EHLO Strings

High Severity Vulnerability Found in Intel Software Let Hackers Perform Escalation of Privilege, DoS Attack

You can follow us on LinkedinTwitterFacebook for daily Cyber Security and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago