Summary
Key Points:
- Payload Ransomware has claimed responsibility for a breach at the Royal Bahrain Hospital, stealing 110 GB of sensitive data and threatening to release it unless a ransom is paid by March 23.
- The impact includes potential exposure of patient data and disruption to healthcare services, affecting not only Bahrain but also neighboring countries like Oman, Qatar, Saudi Arabia, and the UAE.
- Immediate actions recommended include isolating affected systems, enhancing monitoring for unusual activity, and preparing incident response plans for potential data leaks.
Technical Details: The ransomware employs ChaCha20 for file encryption and Curve25519 for key exchange while also deleting shadow copies and disabling security tools to hinder recovery efforts.
MITRE ATT&CK Techniques:
- T1486 - Data Encrypted for Impact (Impact)
- T1490 - Inhibit System Recovery (Impact)
- T1562.001 - Impair Defenses: Disable or Modify Tools (Defense Evasion)
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.