Van Helsing is a ransomware operation referenced in reporting on healthcare-sector ransomware activity in 2025. In the provided content, it is specifically noted for having claimed only one attack on a healthcare organization, but that attack was described as the largest by number of records affected among the healthcare incidents discussed. No additional high-confidence details are provided in the content regarding its malware capabilities, infection vectors, technical behavior, associated threat actors, targeted platforms, or indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group/strain referenced for a high-impact healthcare-related breach by number of records affected.
Ransomware/extortion operation reported to have claimed a major healthcare-related breach by records affected (Compumedics Limited, Australia).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.