The Daixin Team has conducted ransomware and data-extortion operations against U.S. healthcare organizations and later claimed a major airline breach that allegedly exposed employee records and data on five million passengers. U.S. authorities said the group has encrypted servers supporting electronic health records, diagnostics, imaging, and intranet services while also stealing PII and PHI to pressure victims into paying. The ransomware has been linked to leaked Babuk Locker source code and has been deployed against VMware ESXi environments after attackers gained privileged access to vCenter and reset administrative passwords.
Investigators said Daixin commonly gains initial access through vulnerable or weakly protected VPN services and previously compromised credentials obtained through phishing, then moves laterally with SSH and RDP while escalating privileges through credential dumping and pass-the-hash techniques. In the airline case, researchers identified two likely intrusion paths: credential theft tied to infostealer malware activity, including infrastructure associated with RedLine, and attacks against a vulnerable public-facing SSH service. The reporting also linked the incident to broader malicious infrastructure overlap and noted the group’s use of tools such as Rclone and Ngrok for exfiltration, reinforcing guidance to prioritize patching, phishing-resistant MFA, segmented networks, and offline immutable backups.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
An information security researcher reported on November 20 that the Daixin Team claimed responsibility for an attack on an airline and alleged exposure of personal data belonging to all employees and five million passengers.
SecurityScorecard reported especially heavy port 22 traffic involving an airline-attributed IP with vulnerable SSH software on September 23, September 24, September 25, November 3, and November 6, suggesting possible probing or attack activity against the service.
Between September 21 and November 21, 66 files containing the victim airline's domain and linked by vendors to malicious activity were submitted to VirusTotal, including Trojan-labeled HTML and script files.
On October 26, 2022, CISA published a joint #StopRansomware advisory with the FBI and HHS detailing Daixin Team tactics, including VPN-based initial access, credential theft, lateral movement, ESXi encryption, and data exfiltration.
A joint FBI, CISA, and HHS advisory said the Daixin Team had been conducting ransomware and data extortion operations against U.S. Healthcare and Public Health sector organizations since at least June 2022.
SecurityScorecard's STRIKE Team later analyzed the claimed airline incident and identified two plausible, non-mutually exclusive initial access paths: credential theft via infostealer malware and attacks against a vulnerable public-facing SSH service.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcego.recordedfuture.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.