Ransomware Intelligence

insomnia

Ransomware group profile

37Victims
RussiaSource country
70Impact score

Description

Insomnia is a cybercriminal group that began operations in October 2025, focusing on data theft and extortion without encrypting systems. It primarily targets small to mid-sized organizations, particularly in the healthcare sector, using stolen credentials and legitimate tools to evade detection.

Key insights

  • Insomnia uses stolen credentials and exploits authentication bypass vulnerabilities for initial access.
  • The group targets primarily healthcare organizations, threatening public exposure of sensitive data at risk of leakage.
  • Insomnia maintains a low profile during lateral movements by using legitimate administrative tools.
  • The operational model avoids ransomware, instead relying on the threat of data leaks for financial gain.
  • They often steal sensitive records like patient files and tax documents but do not engage in data encryption.
  • Insomnia's tactics focus on speed and low visibility, complicating traditional detection methods.

Threat Level & Status Breakdown

For insomnia · Based on incidents in selected period

4threat level
Aggressiveness7/ 10
Lethality0/ 10
Criticality5/ 10

Status Breakdown

Claimed100.0%37
First seenOct 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 25, 2026

Recent activity

Monthly attack count for insomnia in the selected period

37Total attacks
8peak in Jan
4.1avg / month
↓ 2 vs first month
OctNovDecJanFebMarAprMayJun02468

Intelligence

IOCs, YARA/Sigma rules, and related families for insomnia

  1. 92023d65623cca545802f483cfeabe8ce9f0c3520e0de2edd6eb38460069f25d
View full IOC feed21 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for insomnia

Other

T1078

T1078

T1080

T1080

T1021

T1021

T1021.001

T1021.001

T1562

T1562

T1046

T1046

T1071

T1071

T1210

T1210

T1567

T1567

T1486

T1486

Victims(37)

CompanyDomainCountryIndustryStatusDiscovered
*************
Claimed
about 8 hours ago
*********************.comUS United States
Claimed
about 11 hours ago
Mid-Cumberland Human Resource Agencymchra.comUS United StatesProfessional Services
Claimed
16 days ago
The Vant Groupthevantgroup.comUS United StatesProfessional Services
Claimed
14 days ago
Nephrology AssociatesUS United StatesHealthcare
Claimed
about 2 months ago
METO Systemsmetosystems.comUS United StatesManufacturing
Claimed
2 months ago
United Medical Doctorsunitedmd.comUS United StatesHealthcare
Claimed
3 months ago
Noble Inc.nobleoilfieldservices.comUS United StatesEnergy & Utilities
Claimed
3 months ago
*****d **d**** ****o*****.comUS United StatesHealthcare
Claimed
3 months ago
Atlas Ocean Voyagesatlasoceanvoyages.comUS United StatesHospitality
Claimed
3 months ago
**l** ****** ****** C*******.comUS United StatesHealthcare
Claimed
3 months ago
Valley Family Health Carevfhc.orgUS United StatesHealthcare
Claimed
3 months ago
Belmont Plastic Surgerybelmontplasticsurgeryva.comUS United StatesHealthcare
Claimed
4 months ago
Zaner Groupzaner.comUS United StatesFinancial Services
Claimed
4 months ago
Thrash Commercial Contractorsthrashco.comUS United StatesOther
Claimed
4 months ago
Chiarottinochiarottino.com.brBR BrazilProfessional Services
Claimed
5 months ago
Enviro-Hub Holdingsenviro-hub.comSG SingaporeManufacturing
Claimed
5 months ago
Application Solution Providersaspdd.comUS United StatesTechnology
Claimed
4 months ago
AdMark Asia Groupadmarkasiagroup.comUS United StatesProfessional Services
Claimed
4 months ago
Aviam Corporate Housingaviam.comUS United StatesHospitality
Claimed
4 months ago

Page 1 of 2