Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors insomnia

Description

Insomnia is a data-theft and extortion group that emerged in October 2025, targeting primarily US-based healthcare organizations — stealing patient files and threatening public exposure rather than encrypting files — and avoiding former Soviet states, consistent with Russian-speaking cybercrime norms. Known victims: 34

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Insomnia is a medium-sophistication criminal threat actor identified since February 2025, primarily targeting US-based healthcare organizations. Known for data theft and extortion via threats of public exposure rather than ransomware encryption, Insomnia demonstrates strategic operational choices, such as avoiding former Soviet states—consistent with Russian-speaking cybercrime norms. The group is considered particularly concerning due to its focus on sensitive data in the healthcare sector.

Goals & Targeting

Insomnia's strategic objectives center on financial gain through extortion and the theft of sensitive data, which they leverage for coercive purposes. Their targeting focus on healthcare organizations reflects both the availability of highly sensitive Personally Identifiable Information (PII) and the high stakes involved in protecting patient records—a sector with little tolerance for downtime or data breaches. Insomnia's geographic choices suggest an operational awareness of regional law enforcement capabilities and international relations, particularly concerning former Soviet states.

Enhanced Description

Insomnia emerged in early 2025 as a数据-theft and extortion-focused cybercriminal group. Unlike traditional ransomware operators, Insomnia specializes in stealing patient records and threatening public exposure to coerce victims into paying ransoms or other forms of compensation. This unique approach reflects a strategic shift in tactics, focusing on data integrity and privacy concerns rather than outright encryption. The group has demonstrated persistence and adaptability over its brief operational history, targeting 34 healthcare organizations across the United States as of June 2026. Insomnia's avoidance of former Soviet states aligns with broader trends observed within Russian-speaking cybercrime groups, where such geographic constraints are often imposed to minimize law enforcement attention or avoid geopolitical complications.

Key Capabilities

  • Data exfiltration via malicious insider activities or compromised credentials
  • Threats of public exposure to coerce payments
  • Avoidance of traditional ransomware encryption tactics
  • Targeting of healthcare organizations for sensitive data

MITRE ATT&CK Tactics

Collection
Exfiltration
External Access from Cloud Account/Service

ATT&CK Techniques

T1059.003
T1566.001

Software / Tooling

Cobalt Strike
Custom Malware Frameworks

Campaigns & Victims

Insomnia operates with a steady cadence, launching multiple campaigns against healthcare organizations in the past six months. Their victims include Nephrology Associates, METO Systems, United Medical Doctors, and others in the healthcare sector. Known for their methodical approach, Insomnia uses sophisticated tactics to gain unauthorized access, exfiltrate data, and issue threats. Campaign patterns indicate a preference for email-based social engineering and lateral movement within networks.

IOC Patterns

  • Spear-phishing emails targeting healthcare organizations
  • Compromise of patient data systems via phishing or RDP
  • Exfiltration of sensitive files over encrypted channels
  • Threats of public exposure following data breaches

Recommended Actions

  • Implement multi-factor authentication (MFA) on critical systems and cloud services
  • Conduct regular employee training to identify email-based social engineering attempts
  • Monitor for unauthorized access to sensitive healthcare data repositories
  • Assess external and internal threats using threat intelligence feeds related to Insomnia's known tactics
  • Test incident response plans, including communication with law enforcement and affected individuals

Suggested Tags

APT
Cybercrime
Data Extortion
Healthcare Sector

Confidence Assessment

High confidence in the targeting patterns, tactics, and threat vectors attributed to Insomnia based on observed campaigns. Limited visibility into specific tools or malware used by the group, though their reliance on data exfiltration suggests use of common frameworks such as Cobalt Strike or similar. Further analysis could clarify their exact modus operandi and toolset.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

17

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Healthcare Targeting
APT
Cybercrime
Data Extortion
Healthcare Sector

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 14, 2025
Last Seen
Jul 23, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.