Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors NetRunnerPR

Also known as: tracked as, Aug 5, APT28, Pawn Storm, Fancy Bear, fast16, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Sednit, Royal Ransomware, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

NetRunnerPR has claimed to breach the networks of Shiraume Hospital and Nippon Medical School Musashi Kosugi Hospital in Japan, exfiltrating patient PII and medical records. The actor announced plans to release a complete database on March 5, 2026, and an additional 20,000 records on February 16, 2026, contingent on undisclosed conditions. The claims were made on a cybercrime forum, accompanied by sample data to validate the breaches. NetRunnerPR's account shows limited activity history and lacks a documented history of major ransomware operations or confirmed breaches, raising questions about the credibility of the claims.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Media
Healthcare
Education
Telecommunications
Critical infrastructure
Manufacturing
Information technology
Retail
Non profit
Hospitality
Energy
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation

Targeted Countries / Regions

CN
RU
KP
IN
UA
GB
JP
DE
IR
KR
PK
BY
PL
TW
CA
AU

AI Analysis

· 1 week ago

Executive Summary

NetRunnerPR is an emerging threat actor claiming to breach Japanese healthcare networks, exfiltrating sensitive patient data. While their credibility remains unverified due to limited historical activity, they pose a potential risk to healthcare entities.

Goals & Targeting

NetRunnerPR appears to target the healthcare sector in Japan, focusing on entities with significant PII and sensitive medical records. Their strategic objectives likely involve demonstrating capability or causing disruption, potentially leveraging data leaks as a pressure tactic. The choice of the healthcare sector may reflect its perceived vulnerabilities or high-value assets.

Enhanced Description

NetRunnerPR gained attention by announcing breaches of Shiraume Hospital and Nippon Medical School Musashi Kosugi Hospital in Japan. The actor claimed unauthorized access to patient PII and medical records, with plans to release data contingent on certain conditions. Their claims were supported by sample data on a cybercrime forum. Despite these assertions, NetRunnerPR's activity history is limited, raising questions about the authenticity of their operations. This actor exemplifies emerging threats targeting vulnerable sectors like healthcare, where data breaches can have severe consequences for both organizations and individuals.

Key Capabilities

  • Network breach capability
  • Data exfiltration skills
  • Potential use of malware or tools for unauthorized access

MITRE ATT&CK Tactics

Initial Access
Execution
Exfiltration

ATT&CK Techniques

T1059 - Spear-phishing via email
T1048 - Data transfer to cloud account
T1078 - Valid accounts

Software / Tooling

Custom malware for network breach
Spear-phishing tools

Campaigns & Victims

NetRunnerPR's campaign patterns involve claiming breaches on forums, possibly to pressure organizations. Their limited activity suggests they may be emerging or less sophisticated actors. The targeted healthcare sector indicates a focus on entities with sensitive data.

IOC Patterns

  • Spear-phishing emails targeting healthcare staff
  • Unauthorized network access attempts
  • Scheduled data release announcements

Recommended Actions

  • Enhance healthcare network security protocols
  • Monitor for异常 exfiltration activities
  • Train employees to recognize phishing
  • Conduct regular vulnerability assessments

Suggested Tags

APT
Healthcare Sector
Data Exfiltration
Japan

Confidence Assessment

Confidence in NetRunnerPR's claims is moderate. While the actor provided sample data, the lack of verified history creates uncertainty about their legitimacy.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  2. attack.mitre.org — Cited by web research for: services
  3. attack.mitre.org — Cited by web research for: Interception

Intel Summary

40

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
Healthcare Targeting
Data Exfiltration
APT
Healthcare Sector
Japan

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.