On September 19, 2024, Microsoft reported that the financially motivated threat actor Vanilla Tempest had used INC ransomware against U.S. healthcare organizations. Microsoft described this as its first observed use of INC against healthcare targets. This is a retrospective account of that 2024 warning, not a newly announced 2026 incident.
What Microsoft reported
Microsoft tracked the actor as Vanilla Tempest, also known in public reporting as Vice Society and previously tracked by Microsoft as DEV-0832. The warning concerned U.S. healthcare organizations and INC ransomware. Those are vendor and reporting labels; overlap in names does not, by itself, prove that every incident attributed to one label involved the same operators.
The account was reported on September 19, 2024, with further technical summaries from SecurityWeek and TechRadar. Microsoft’s observation is not a public law-enforcement attribution, nor does it establish that every intrusion using INC came from Vanilla Tempest.
How the reported intrusion chain worked
Microsoft’s account describes a sequence in which pre-existing access, ordinary administration utilities, and ransomware were combined. The sequence is useful for defenders to investigate, but it should not be treated as a guaranteed checklist for every incident.
#1 Best Overall
- Access handoff: Vanilla Tempest received access from systems already infected with Gootloader, which Microsoft attributed to Storm-0494.
- Persistence and supporting tools: The actor used the Supper backdoor, the legitimate AnyDesk remote-management product, and MEGA, a cloud synchronization service that could support data movement.
- Movement inside the network: Remote Desktop Protocol (RDP) was used for lateral movement.
- Ransomware deployment: Windows Management Instrumentation (WMI) Provider Host was used to deploy the INC payload.
- Potential extortion: The activity could involve data theft as well as encryption. MEGA use makes exfiltration a relevant possibility, but the reporting does not establish that patient data was stolen in every affected case.
AnyDesk, MEGA, RDP, and WMI all have legitimate uses. Their presence alone is not proof of compromise. Investigators should examine which account and device used them, whether the activity fit an approved workflow, the process that launched the tool, the timing, destinations, and surrounding administrative actions.
Who is Vanilla Tempest, and what is INC?
Vanilla Tempest is described in reporting as financially motivated and associated with attacks across education, healthcare, information technology, and manufacturing. Its reported use of different ransomware families—including BlackCat, Quantum Locker, Zeppelin, Rhysida, and INC—means defenders should not rely on a single ransomware brand as an indicator of the actor’s presence.
INC is a ransomware strain that secondary reporting describes as operating through a ransomware-as-a-service model. In that model, a core operator may provide malware or infrastructure while affiliates conduct intrusions; the division of work can vary. Microsoft’s reporting supports saying Vanilla Tempest used or deployed INC, not that it owned or developed the ransomware. INC has also been associated with data theft and extortion tooling.
What the warning did not establish
- Microsoft did not name the healthcare organization or organizations involved.
- The reporting did not establish the number of victims, whether a ransom was demanded or paid, or a campaign success rate.
- It did not establish that every intrusion resulted in encryption. The group has also been associated with data-only extortion.
- An incident involving INC is not, on its own, proof of Vanilla Tempest attribution. Unrelated healthcare incidents should not be assigned to this campaign without evidence.
Why this matters to healthcare organizations
Healthcare combines sensitive personal information with systems that support time-dependent clinical work. Disruption can affect scheduling, diagnostics, pharmacy operations, billing, emergency workflows, and access to electronic health records. Stolen information can create privacy, contractual, regulatory, and breach-notification consequences even if systems are restored from backups.
Rank #3
The U.S. Department of Health and Human Services describes ransomware as a disruptive risk to hospital operations in its hospital resiliency analysis and identifies common attack vectors addressed by its healthcare cybersecurity performance goals. The practical implication is not that every ransomware incident causes the same harm, but that recovery planning must account for clinical availability as well as data confidentiality.
What healthcare defenders should check
Identity and remote access
- Require strong MFA, preferably phishing-resistant MFA where feasible, for remote access and privileged accounts.
- Remove direct internet exposure of RDP where possible; restrict remaining access by network segment, user, device, and administrative role.
- Investigate unusual RDP logons, particularly from unmanaged devices, unfamiliar locations, or accounts that do not ordinarily administer servers.
- Compare AnyDesk and other remote-management tools with an approved software inventory. Disable or isolate unauthorized installations while preserving documented support workflows.
Endpoints, servers, and WMI
- Maintain endpoint detection and response coverage across workstations and servers, and protect security tools against tampering.
- Review WMI activity when it originates from unusual parent processes or coincides with service creation, credential access, remote execution, or mass file changes.
- Use attack-surface-reduction controls to limit scripting abuse, credential theft, and unauthorized remote execution; keep security intelligence current.
- Check that monitoring covers relevant Windows, Linux, macOS, mobile, IoT, and network-connected assets where the organization’s tooling supports them. Medical devices that cannot run conventional agents may need network monitoring and vendor-coordinated patching.
Data movement and backup resilience
- Investigate unexpected MEGA or other synchronization-tool activity, especially on servers or administrator workstations, and monitor unusual outbound transfers from file servers, EHR-adjacent systems, identity stores, and backup infrastructure.
- Keep investigation logs long enough to examine activity that may precede encryption by days or weeks.
- Separate backup credentials and networks from routine domain administration, and maintain offline or otherwise ransomware-resilient backups.
- Test restoration of clinical systems, identity services, picture archiving and communication systems (PACS), pharmacy, laboratory, and communications services. A backup is only useful operationally if critical systems can be restored in time.
Clinical operations, vendors, and response
- Document downtime procedures for patient care and define who may authorize isolating a critical system so containment does not create avoidable clinical disruption.
- Include business associates, outsourced billing, laboratories, managed-service providers, and remote-support vendors in access reviews and incident exercises.
- Run tabletop exercises with clinical leadership, IT, legal, privacy, communications, law enforcement, cyber-insurance contacts, and relevant vendors.
- Connect technical response to HIPAA Security Rule risk analysis, safeguards, workforce training, contingency planning, and breach-notification duties. HHS OCR’s April 2026 ransomware-related settlements and June 2026 settlement illustrate that ransomware response and compliance remain consequential beyond the 2024 warning.
Detection priorities and trade-offs
Useful investigation leads include unexpected internal RDP connections; WMI Provider Host activity that launches processes or reaches multiple endpoints; remote-management software outside approved support sessions; synchronization clients on servers; Gootloader-related detections preceding later movement; Supper detections or anomalous persistence; and rapid mass file changes, shadow-copy deletion, backup tampering, or encryption behavior. A sequence combining credential use, RDP, WMI, remote-tool execution, and high-volume outbound transfers merits prompt investigation. These are hunting ideas, not guaranteed indicators of compromise.
Rank #4
Blocking every legitimate administration or storage tool can interrupt care and support. Prefer allowlisting, role-based exceptions, segmentation, and review of context over indiscriminate blocking. Similarly, endpoint isolation and network segmentation need healthcare-specific authorization paths. Encryption recovery and data-theft response are separate problems: backups can help restore systems, but cannot reverse exfiltration.
Microsoft documents Defender for Endpoint capabilities that include endpoint detection and response, attack-surface reduction, automated investigation and remediation, vulnerability management, and ransomware-related reporting on its product page, threat-protection reporting documentation, and tamper-resiliency guidance. Actual protection depends on licensing, deployment, telemetry, policy configuration, and operational follow-through. Endpoint software does not replace identity governance, network segmentation, resilient backups, third-party access controls, or clinical downtime planning.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




