Daixin Team
- First seen
- 2022-06-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:10:42
Targeted industries: healthcare-and-pharmaceutical defense-and-aerospace manufacturing energy-and-utilities
Targeted regions: country_code:us
Context
Daixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware attacks, stealing sensitive data and threatening to release it if a ransom is not paid. They have successfully targeted various industries, including healthcare, aerospace, automotive, and packaged foods. Daixin gains initial access through VPN servers and exploits vulnerabilities or uses phishing attacks to obtain credentials. They have been responsible for cyberattacks on organizations such as the North Texas Municipal Water District and TransForm Shared Service Org, impacting their networks and stealing customer and patient information.
Reports & references
- CISA — Aa22 294A (report)
- mycert.org.my — Details (report)
- databreaches.net — B Files Leaked (report)
- titaniam.io — Ransomware Prevention Daixin Team Ransomware Group (report)
- databreaches.net — Update Daixin Leaks More Data From Bluewater Health And Other Hospitals Databases Yet To Be Leaked (report)