Bitter Pill

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Huntress uncovered a cyberattack targeting multiple healthcare organizations — including pharmacies — through a compromised ScreenConnect instance tied to Transaction Data Systems (now Outcomes), makers of Rx30 and ComputerRx pharmacy software. Threat actors used the legitimate remote access tool for initial access, then installed additional ScreenConnect and AnyDesk instances for persistence. Post-access activity included downloading a C# Meterpreter loader via MSBuild, credential harvesting via WDigest registry modification, Active Directory enumeration, and network scanning. IOCs include four malicious IPs, file hashes, ScreenConnect instance IDs, and an open directory hosting tools including a Veeam CVE-2023-27532 exploit. Huntress urges all Transaction Data Systems/Outcomes clients to immediately check for these IOCs and recommends enhanced endpoint monitoring and proactive threat hunting.

8m read timeFrom huntress.com
Post cover image
Table of contents
OverviewTechnical Indicators of Compromise (IoCs)Mitigation Guidance