Daixin Team

First seen
2022-06-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:10:42

Targeted industries: healthcare-and-pharmaceutical defense-and-aerospace manufacturing energy-and-utilities

Targeted regions: country_code:us

Context

Daixin is a threat actor group that has been active since at least June 2022. They primarily target the healthcare and public health sector with ransomware attacks, stealing sensitive data and threatening to release it if a ransom is not paid. They have successfully targeted various industries, including healthcare, aerospace, automotive, and packaged foods. Daixin gains initial access through VPN servers and exploits vulnerabilities or uses phishing attacks to obtain credentials. They have been responsible for cyberattacks on organizations such as the North Texas Municipal Water District and TransForm Shared Service Org, impacting their networks and stealing customer and patient information.

Reports & references

  • CISA — Aa22 294A (report)
  • mycert.org.my — Details (report)
  • databreaches.net — B Files Leaked (report)
  • titaniam.io — Ransomware Prevention Daixin Team Ransomware Group (report)
  • databreaches.net — Update Daixin Leaks More Data From Bluewater Health And Other Hospitals Databases Yet To Be Leaked (report)

External references