WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Joint Cybersecurity Advisory – #StopRansomware: Daixin Team
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Joint Cybersecurity Advisory – #StopRansomware: Daixin Team

Author: Alec Davison

Created: Tuesday, October 25, 2022 - 19:09

Categories: Cybersecurity

Last week, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS) published a joint Cybersecurity Advisory (CSA) to provide information on the “Daixin Team,” a cybercrime group actively targeting U.S. businesses, predominantly in the Healthcare and Public Health (HPH) Sector, with ransomware and data extortion operations. 

Daixin Team is believed to have been in operation since at least June 2022. According to the FBI IC3 data, the Daixin Team has targeted all U.S. critical infrastructure sectors. Reporting indicates that after gaining initial access through victims’ virtual private networks (VPN) servers, the threat actors moved laterally “seeking to gain privileged account access so they could ultimately reset account passwords for ESXi servers in the environment. Then, the actors used secure shell (SSH) to connect to accessible ESXi servers and deploy ransomware, which is based on leaked Babuk Locker source code that targets ESXi services and encrypts files.” In addition to deploying ransomware, Daixin threat actors have exfiltrated data from victim devices using an open-source program, rclone, or a reverse proxy tool, Ngrok. 

The joint CSA also provides tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), and recommended mitigations to help organizations defend against this threat. To report suspicious or criminal activity related to information found in advisory, contact your local FBI field office, or the FBI’s 24/7 Cyber Watch (CyWatch) at (855) 292-3937, or by e-mail at Cy*****@*bi.gov. If you have any further questions, or to request incident response resources or technical assistance related to these threats, contact CISA at CI*************@******hs.gov. Access the full advisory at CISA.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 11, 2026)

Jun 11, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – June 11, 2026

Jun 11, 2026 in Cybersecurity
Members Only

(TLP:GREEN) FBI Report – Elevated Cyber Risk to Utility Providers Supporting FIFA World Cup 2026 Tournament Events

Jun 11, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar