HC3 warns of Clop ransomware targeting medical images

The Health Sector Cybersecurity Coordination Center said in its latest analysis that the Clop ransomware gang has shifted tactics, directly impacting the healthcare and public health sector. 

New baiting tactics for ransomware gang 

While Clop ransomware has been around since 2019 and experienced several arrests, the ransomware-as-a-service operation has had difficulties getting victims to pay the ransom. 

HC3, which released several ransomware warnings in 2022, including one about the exceptionally aggressive Hive ransomware that seeks to delete healthcare data backups, says that Clop has been infecting files and disguising them to look like medical documents to be reviewed.

They are “submitting them to facilities, and then requesting a medical appointment in hopes of those malicious documents being opened and reviewed beforehand,” the agency said in the analysis.

“These attacks have a higher chance of working due to conditions from COVID-19 expansion in the telehealth environment.”

The agency also indicates that Clop, or CLOp, targets Windows and sends phishing emails to gain entry. It’s also known to have resistance to anti-analysis virtual-machine analysis. 

After files are encrypted, they drop a ransom note saying that the stolen files will be deleted after two weeks.

Targeting telehealth

Medical providers continue to expand telehealth to increase access, improve care and reach more patients – and revenues are high.

Last month KrebsOnSecurity reported about Clop after seeing an intercepted communication in which the group indicated it was successful in infiltrating new victims by disguising ultrasound images and other medical documents.

In the report, Alex Holden, founder of Hold Security, a Milwaukee-based cybersecurity firm, said the group is strategically targeting the types of medical conditions they perceive to be more easily diagnosed via telehealth.

“Basically, they’re counting on doctors or nurses reviewing the patient’s chart and scans just before the appointment,” Holden said. 

“They initially discussed going in with cardiovascular issues, but decided cirrhosis or fibrosis of the liver would be more likely to be diagnosable remotely from existing test results and scans.”

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS publication.

Read More
Alejandro Mote

Latest

Inside the $9 billion World Cup: How Gianni Infantino built a FIFA-dom with a tight grip on soccer’s biggest global event

For Zurich’s bankers and executives, May 27, 2015, began as a normal Wednesday—until Swiss police stormed the financial hub’s five-star Baur au Lac hotel and arrested seven top officials of FIFA, soccer’s global governing body, who were gathered there for their annual congress. The U.S. Department of Justice had unsealed a sprawling indictment alleging payment

Deel Launches DLUSD to Pay Workers in Dollars — No US Bank Needed

Two announcements from traditional financial powerhouses this week signal that stablecoins are becoming the plumbing of everyday finance. Getting Paid in Stablecoins Deel, the global payroll platform serving 40,000 businesses and 1.5 million workers across 150 countries, launched DLUSD on June 3, a custom USD-backed stablecoin...

Coinbase freezes $3M tied to Southeast Asia crypto fraud networks

Coinbase freezes $3M tied to Southeast Asia crypto fraud networks Latest News Published Jun 4, 2026 Authorities around the world have been heavily targeting scam infrastructure this year, with joint actions involving the US, UAE, China, Austria and Albania. Crypto exchange Coinbase said it froze more than $3 million in cryptocurrency tied to a global

Morgan Stanley sees major upside for Apple stock ahead of WWDC

Please enable JS and disable any ad blocker

Newsletter

Don't miss

Inside the $9 billion World Cup: How Gianni Infantino built a FIFA-dom with a tight grip on soccer’s biggest global event

For Zurich’s bankers and executives, May 27, 2015, began as a normal Wednesday—until Swiss police stormed the financial hub’s five-star Baur au Lac hotel and arrested seven top officials of FIFA, soccer’s global governing body, who were gathered there for their annual congress. The U.S. Department of Justice had unsealed a sprawling indictment alleging payment

Deel Launches DLUSD to Pay Workers in Dollars — No US Bank Needed

Two announcements from traditional financial powerhouses this week signal that stablecoins are becoming the plumbing of everyday finance. Getting Paid in Stablecoins Deel, the global payroll platform serving 40,000 businesses and 1.5 million workers across 150 countries, launched DLUSD on June 3, a custom USD-backed stablecoin...

Coinbase freezes $3M tied to Southeast Asia crypto fraud networks

Coinbase freezes $3M tied to Southeast Asia crypto fraud networks Latest News Published Jun 4, 2026 Authorities around the world have been heavily targeting scam infrastructure this year, with joint actions involving the US, UAE, China, Austria and Albania. Crypto exchange Coinbase said it froze more than $3 million in cryptocurrency tied to a global

Morgan Stanley sees major upside for Apple stock ahead of WWDC

Please enable JS and disable any ad blocker

Why Your Business Could Lose More Than Its Founder If You’re Suddenly Incapacitated

If your business depends entirely on you for access to critical information, one emergency can put everything at risk. Here's how to build a continuity plan before that ever happens...

Jury acquits 2 business executives of bribing Navy admiral for government contract

A federal jury has acquitted two business executives of charges that they conspired to bribe a retired four-star U.S. Navy admiral, who is now serving a six-year prison sentence for his conviction on corruption charges By MICHAEL KUNZELMAN Associated Press WASHINGTON -- A federal jury has acquitted two business executives of charges that they conspired

US Business Leaders Optimistic About China Cooperation, Emphasize Importance of Chinese Market

© 2026 China Money Network. All Rights Reserved. Disclaimer: The views, opinions, forecasts, and statements made by our hosts and guests are the personal views of those respective individuals and may or may not be either endorsed or accepted by China Money Network Limited or the companies with which these individuals are employed.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they