Daixin Team, also known as Daixin and Daixin Group, is a financially motivated cybercriminal group conducting ransomware and data-extortion operations since at least June 2022. It predominantly targets U.S. healthcare and public health organizations, including hospitals and ambulance services, and has also attacked Malaysia's aviation sector. Its victims include OakBend Medical Center, Fitzgibbon Hospital, Acadian Ambulance Service, and AirAsia Group. The group combines encryption with theft of personally identifiable information and protected health information, threatening publication and posting victims to a dedicated leak site to pressure them into paying. Daixin gains initial access through compromised VPN credentials and exploitation of unpatched VPN vulnerabilities. Its credential-acquisition methods include phishing emails with malicious attachments. After gaining access, the group moves laterally using SSH and Remote Desktop Protocol, including remote-session hijacking, and obtains privileged access through credential dumping and pass-the-hash. It uses privileged accounts to access VMware vCenter, resets ESXi account passwords, and connects to ESXi hosts through SSH to deploy ransomware. Daixin's ESXi-targeting ransomware is derived from leaked Babuk Locker source code and encrypts virtual-machine files. Healthcare incidents have affected servers supporting electronic health records, diagnostics, imaging, and intranet services. The group has used Rclone to transfer stolen data to a dedicated virtual private server and Ngrok for exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another extortion group known for refusing low payment offers and leaking data to reinforce credibility in future negotiations.
The Daixin ransomware group claims to have compromised Fitzgibbon Hospital in the United States and states that stolen data has been published. The post alleges theft of MEDITECH database table dumps and 40 GB of sensitive internal documents, including emails in PDF form and scanned records containing PII and PHI.
The daixin ransomware group claims Trib Total Media in the United States as a victim and states that stolen data from internal file servers totaling 2 GB has been published. The post identifies the victim website and indicates the leak is a full release marked as expired.
The Daixin ransomware group claims it compromised ISTA International GmbH and states that 458 GB of sensitive internal file server documents were stolen and published. The post references multiple Germany and France leak segments and indicates the full leak status as expired.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.