Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

insomnia Ransomware Group

Ransomware group profile

46Victims
RussiaSource country
71Impact score

Description

Insomnia is a cybercriminal group that began operations in October 2025, focusing on data theft and extortion without encrypting systems. It primarily targets small to mid-sized organizations, particularly in the healthcare sector, using stolen credentials and legitimate tools to evade detection.

Key insights

  • Insomnia uses stolen credentials and exploits authentication bypass vulnerabilities for initial access.
  • The group targets primarily healthcare organizations, threatening public exposure of sensitive data at risk of leakage.
  • Insomnia maintains a low profile during lateral movements by using legitimate administrative tools.
  • The operational model avoids ransomware, instead relying on the threat of data leaks for financial gain.
  • They often steal sensitive records like patient files and tax documents but do not engage in data encryption.
  • Insomnia's tactics focus on speed and low visibility, complicating traditional detection methods.

Threat Level & Status Breakdown

For insomnia · Based on incidents in selected period

No victim data for this group in the selected period.

First seenOct 2025
Last seenAug 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 11, 2026

Recent activity

Monthly attack count for insomnia in the selected period

46Total attacks
8peak in Jan
4.6avg / month
↑ 4 vs first month
OctNovDecJanFebMarAprMayJulAug02468

Intelligence

IOCs, YARA/Sigma rules, and related families for insomnia

  1. 92023d65623cca545802f483cfeabe8ce9f0c3520e0de2edd6eb38460069f25d
View full IOC feed3 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for insomnia

Other

T1078

T1078

T1080

T1080

T1021

T1021

T1021.001

T1021.001

T1562

T1562

T1046

T1046

T1071

T1071

T1210

T1210

T1567

T1567

T1486

T1486