Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Daixin Team

Description

Daixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware attacks, stealing sensitive data and threatening to release it if a ransom is not paid. They have successfully targeted various industries, including healthcare, aerospace, automotive, and packaged foods. Daixin gains initial access through VPN servers and exploits vulnerabilities or uses phishing attacks to obtain credentials. They have been responsible for cyberattacks on organizations such as the North Texas Municipal Water District and TransForm Shared Service Org, impacting their networks and stealing customer and patient information.

AI Analysis

· 1 week ago

Executive Summary

Daixin Team is an active cyber threat actor primarily targeting healthcare, aerospace, automotive, and packaged foods sectors with ransomware attacks. They exploit vulnerabilities or use phishing to gain initial access through VPN servers, steal sensitive data, and demand ransoms for its release. Their activities have impacted critical infrastructure organizations如 the North Texas Municipal Water District and TransForm Shared Service Org.

Goals & Targeting

Daixin Team's strategic objectives appear to be primarily financial in nature, leveraging ransomware to extort payments from victims. Their targeting profile demonstrates a focus on sectors with sensitive or valuable data, such as healthcare, which holds personally identifiable information (PII) and patient records. By preying on industries like aerospace and automotive, Da Xin Team may be seeking high-value intellectual property (IP) or operational data that could also be used for economic gain through sale on the black market or disruption of service.

Enhanced Description

Daixin Team is a cyber threat group that has been active since June 2022. They are known for conducting ransomware attacks, particularly targeting the healthcare and public health sectors. Their modus operandi involves gaining unauthorized access to victim networks through VPN servers, exploiting vulnerabilities, or deploying phishing campaigns to obtain credentials. Once inside, they deploy ransomware to encrypt sensitive data and demand payment in exchange for its decryption key. Daixin has targeted a wide range of industries, including aerospace, automotive, and packaged foods, indicating a versatile operational approach. Their attacks often result in significant financial loss and reputational damage, as well as the potential exposure of sensitive data if demands are not met. The group’s activities highlight their ability to disrupt critical infrastructure and their focus on maximizing financial gain through malicious cyber activity.

Key Capabilities

  • Ransomware deployment
  • Vulnerability exploitation
  • Phishing campaigns
  • VPN server compromise
  • Data exfiltration

MITRE ATT&CK Tactics

Piracy
Exfiltration
Defense Evasion
Disruption

ATT&CK Techniques

T1059.003
T1078
T1021
T1566
T1055

Software / Tooling

Ransomware (未知具体名称)
Phishing tools (e.g., QakBot, Trickbot})
Custom exploit code for VPN vulnerabilities

Campaigns & Victims

Daixin Team's campaign patterns indicate a focus on critical infrastructure and data-rich industries. They have demonstrated the ability to successfully compromise organizations such as municipal water districts and healthcare providers, suggesting a capability to target both public and private sector entities. Their operational tempo suggests they are active and adaptive, with campaigns likely coordinated to maximize impact. Notable past operations include attacks targeting municipal services in North Texas and healthcare organizations where sensitive patient data was stolen. These actions underscore their intent to disrupt victim organizations while exploiting fear of data exposure to coerce payments.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • Exploits targeting VPN server vulnerabilities
  • Network traffic anomalies consistent with lateral movement
  • Ransomware encryption patterns in file systems

Recommended Actions

  • Implement multi-factor authentication (MFA) for remote access and VPN services.
  • Conduct regular vulnerability scans and penetration testing to identify and patch vulnerabilities.
  • Enhance email filtering and user training to mitigate phishing risks.
  • Monitor network traffic for signs of unauthorized access or lateral movement.
  • Maintain offline backups of critical data and establish an incident response plan for ransomware events.

Suggested Tags

Ransomware
Healthcare sector targeting
Critical Infrastructure
Phishing

Confidence Assessment

The confidence in this assessment is high due to the availability of specific details about Daixin Team's activities, including their targets and TTPS. However, some gaps remain regarding their exact motivations, sophistication level, and the full range of tools used. Additional clarity on these aspects would strengthen the understanding of their threat profile.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Critical Infrastructure
Phishing
Data Exfiltration
Healthcare sector targeting

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.