Ransomware Intelligence

insomnia

Ransomware group profile

33Victims
RussiaSource country
69Impact score

Description

Insomnia is a cybercriminal group that began operations in October 2025, focusing on data theft and extortion without encrypting systems. It primarily targets small to mid-sized organizations, particularly in the healthcare sector, using stolen credentials and legitimate tools to evade detection.

Key insights

  • Insomnia uses stolen credentials and exploits authentication bypass vulnerabilities for initial access.
  • The group targets primarily healthcare organizations, threatening public exposure of sensitive data at risk of leakage.
  • Insomnia maintains a low profile during lateral movements by using legitimate administrative tools.
  • The operational model avoids ransomware, instead relying on the threat of data leaks for financial gain.
  • They often steal sensitive records like patient files and tax documents but do not engage in data encryption.
  • Insomnia's tactics focus on speed and low visibility, complicating traditional detection methods.

Threat Level & Status Breakdown

For insomnia · Based on incidents in selected period

3.3threat level
Aggressiveness5/ 10
Lethality0/ 10
Criticality5/ 10

Status Breakdown

Claimed100.0%33
First seenOct 2025
Last seenApr 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for insomnia in the selected period

33Total attacks
8peak in Jan
4.7avg / month
↑ 1 vs first month
OctNovDecJanFebMarApr02468

Intelligence

IOCs, YARA/Sigma rules, and related families for insomnia

  1. 92023d65623cca545802f483cfeabe8ce9f0c3520e0de2edd6eb38460069f25d
View full IOC feed21 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for insomnia

Other

T1078

T1078

T1080

T1080

T1021

T1021

T1021.001

T1021.001

T1562

T1562

T1046

T1046

T1071

T1071

T1210

T1210

T1567

T1567

T1486

T1486

Victims(33)

CompanyDomainCountryIndustryStatusDiscovered
Nephrology AssociatesUS United StatesHealthcare
Claimed
about 1 month ago
METO Systemsmetosystems.comUS United StatesManufacturing
Claimed
about 1 month ago
United Medical Doctorsunitedmd.comUS United StatesHealthcare
Claimed
about 2 months ago
Noble Inc.nobleoilfieldservices.comUS United StatesEnergy & Utilities
Claimed
about 2 months ago
*****d **d**** ****o*****.comUS United StatesHealthcare
Claimed
2 months ago
Atlas Ocean Voyagesatlasoceanvoyages.comUS United StatesHospitality
Claimed
2 months ago
**l** ****** ****** C*******.comUS United StatesHealthcare
Claimed
3 months ago
Valley Family Health Carevfhc.orgUS United StatesHealthcare
Claimed
3 months ago
Belmont Plastic Surgerybelmontplasticsurgeryva.comUS United StatesHealthcare
Claimed
3 months ago
Zaner Groupzaner.comUS United StatesFinancial Services
Claimed
3 months ago
Thrash Commercial Contractorsthrashco.comUS United StatesOther
Claimed
3 months ago
Chiarottinochiarottino.com.brBR BrazilProfessional Services
Claimed
4 months ago
Enviro-Hub Holdingsenviro-hub.comSG SingaporeManufacturing
Claimed
4 months ago
Aviam Corporate Housingaviam.comUS United StatesHospitality
Claimed
4 months ago
Dunn and Dunndunnanddunn.comUS United StatesProfessional Services
Claimed
4 months ago
Copier Careerscopiercareers.comUS United StatesProfessional Services
Claimed
4 months ago
AdMark Asia Groupadmarkasiagroup.comUS United StatesProfessional Services
Claimed
4 months ago
The Syverson Groupthesyversongroup.comUS United StatesProfessional Services
Claimed
4 months ago
Application Solution Providersaspdd.comUS United StatesTechnology
Claimed
4 months ago
Optimum Health Instituteoptimumhealth.orgUS United StatesHealthcare
Claimed
4 months ago

Page 1 of 2

Affected countries(9)

Countries where this group has been reported to target or leak victims.