Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Campaigns aurora: Primed Halberstadt Medizintechnik

aurora: Primed Halberstadt Medizintechnik

TLP:CLEAR
Inactive

AI Analysis

No AI analysis yet.

Description

Ransomware attack attributed to aurora. | Country: DE | Sector: Healthcare | Website: Primed Halberstadt Medizintechnik | [manufacturer] *** GmbH — a German manufacturer of medical devices founded in 1946 and now part of the PE-backed PP Medtech group (Wiesmann & Co. KG). The exfiltration captured four entire server volumes: Daten (883 GB) — File server: 289 employee home directories (547 GB), Czech subsidiary data (66 GB), production processes (162 GB), machine configurations (81 GB) EE (807 GB) — Enterprise system: Apollo ERP, VBANK banking (8 accounts), complete database backup (100.6 GB, dated June 3), product images WINDVSW1 (344 GB) — Windows server: DATEV accounting (115+ data directories including LODAS payroll), bank transfers, DMS exports dmsscan (12 GB) — Scanned documents from 51+ employee DMS mailboxes A database backup (spiel.zip.001–010, 100.6 GB) was created on 2026-06-03 | Source: https://www.ransomware.live/id/UHJpbWVkIEhhbGJlcnN0YWR0IE1lZGl6aW50ZWNobmlrQGF1cm9yYQ==

Details

Confidence
80%
First Seen
Jun 30, 2026
Last Seen
Jun 30, 2026
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.