Attackers used the low-cost Philadelphia ransomware to run targeted campaigns against healthcare institutions and other organizations in the same city, delivering malware through spoofed internal-looking emails themed around patients and linked via bit.do URLs. The operation stood out because ransom notes were customized with victim organization names, demanded 15 Bitcoin, and threatened to delete files on a timed schedule, showing a level of personalization more often associated with higher-end ransomware operations.
Proofpoint reported that Philadelphia supported multiple delivery paths, including zipped executables linked from emails, macro-enabled Word documents that launched PowerShell, bundled installers on keygen and cracking sites, and distribution through the Sundown and RIG exploit kits. Its server-side configuration let operators set ransom amounts, Bitcoin addresses, victim IDs, and payment confirmation requirements, underscoring how commodity ransomware had evolved into a flexible platform for more tailored and aggressive attacks.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Proofpoint reported that the Philadelphia ransomware variant was first observed in September of the previous year. The malware was notable for being easy for low-skill actors to customize and deploy.
Proofpoint reported Philadelphia ransomware being bundled with keygen programs and Bitcoin-related software on keygen and cracking sites. The malware was also observed distributed through the Sundown and RIG exploit kits.
The report states this was the first observed instance of Philadelphia ransomware customizing ransom notes for a named victim organization. This showed operators could personalize extortion demands beyond generic commodity ransomware behavior.
Proofpoint described a related healthcare campaign by the same actor in which URLs led victims to macro-enabled Microsoft Word documents. One document, CV.doc, used macros and PowerShell to download Philadelphia ransomware.
A recent campaign targeted specific healthcare institutions and other organizations in the same city using spoofed internal-looking emails with patient-themed lures and bit.do links. In at least one case, the attackers customized the ransom note with the victim organization's name, demanded 15 Bitcoin, and threatened to delete 99 files every 45 minutes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.