Ransomware needs a way in. Stolen credentials are the cheapest one.
insomnia Ransomware Group
Ransomware group profile
Description
Insomnia is a cybercriminal group that began operations in October 2025, focusing on data theft and extortion without encrypting systems. It primarily targets small to mid-sized organizations, particularly in the healthcare sector, using stolen credentials and legitimate tools to evade detection.
Key insights
- •Insomnia uses stolen credentials and exploits authentication bypass vulnerabilities for initial access.
- •The group targets primarily healthcare organizations, threatening public exposure of sensitive data at risk of leakage.
- •Insomnia maintains a low profile during lateral movements by using legitimate administrative tools.
- •The operational model avoids ransomware, instead relying on the threat of data leaks for financial gain.
- •They often steal sensitive records like patient files and tax documents but do not engage in data encryption.
- •Insomnia's tactics focus on speed and low visibility, complicating traditional detection methods.
Threat Level & Status Breakdown
For insomnia · Based on incidents in selected period
No victim data for this group in the selected period.
Recent activity
Monthly attack count for insomnia in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for insomnia
- 92023d65623cca545802f483cfeabe8ce9f0c3520e0de2edd6eb38460069f25d
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for insomnia
T1078
T1078
T1080
T1080
T1021
T1021
T1021.001
T1021.001
T1562
T1562
T1046
T1046
T1071
T1071
T1210
T1210
T1567
T1567
T1486
T1486
Affected countries(11)
Countries where this group has been reported to target or leak victims.