Securing Patient Data at Cullman Regional Medical Center
Discover how Cullman Regional Medical Center safeguards patient data with Darktrace AI. Learn how to keep sensitive data protected with the Darktrace experts!
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Sean Simpson
Executive Director of IT, Cullman Regional Medical Center (Guest Contributor)
Share
26
Oct 2022
Cullman Regional Medical Center strives to improve the health of our community by providing excellent medical resources. We have over 50 providers offering a wide range of specialized care across our offices in Cullman and Hartselle, Alabama.
To deliver the best services possible, we rely on technology. Staff members record medical histories in digital files. Guests interact with us through online portals. Medical IoT devices collect patient data. Yet the same digital adoptions that make healthcare more efficient also present vulnerabilities that threat actors can exploit to gain access to our digital systems.
Another major concern comes from insider threat, whether malicious or accidental. Data security depends on user compliance, which can be hard to enforce and monitor. Even unintentionally, medical professionals can introduce risk simply by bringing personal devices, such as smart phones or watches, into the network.
In late 2020, the FBI, CISA, and HHS issued a warning after the number of cyber-attacks targeting the healthcare sector reached record highs. The agencies cautioned that cybercriminals could exploit malware like TrickBot to harvest credentials, hijack resources to mine crypto-currencies, exfiltrate data, and deploy ransomware.
The attacks targeting the healthcare sector have gone up in frequency and complexity. While protecting our digital infrastructure and patient data has become increasingly difficult, it remains vitally important. That’s why we deployed Darktrace.
High stakes healthcare security
The consequences of cyber-attacks in medicine can be devastating. Lost or stolen medical records can damage a hospital’s reputation and cost millions of dollars. According to a Ponemon Institute study, the financial cost of a data breach in the healthcare sector can cost two to three times more than a breach in any other industry.
Beyond reputational or financial harm, cyber-attacks against hospitals and clinics can be lethal. They can force ambulances to be re-routed, surgeries to be postponed, and treatment options to be scaled back. In 2021, over 45 million patients were impacted by cyber-attacks on healthcare centers, and almost 25% of Health Delivery Organizations found that cyber-attacks increased patient mortality rates.
Darktrace protects our digital infrastructure to avoid these consequences. Its Self-Learning AI learns our organization— from the laptops and servers to the IoT devices to the users themselves— to recognize what constitutes our “pattern of life.” The AI then uses this information to identify the subtle behaviors that indicate a cyber-attack. Once an attack is detected, Autonomous Response reacts with surgical precision to neutralize it without disrupting our normal digital activity.
Darktrace is always on and can detect and respond to attacks within seconds, providing another layer of security for our hospital and clinics. Darktrace’s approach, based on understanding our organization to create bespoke security, allows the AI to spot threats that slip by traditional security tools, which rely on rules and signatures. In this way, Darktrace can detect insider threats, too.
Finally, not only does Darktrace protect us by stopping cyber-attacks, but it also serves as a deterrent to threat actors by making us a harder target.
Protection in action
Darktrace has successfully helped us monitor and protect our digital estate. We have used it to examine suspicious traffic and troubleshoot access related problems. Darktrace’s Cyber AI Analyst investigates attacks and translates its findings into understandable explanations displayed in a single screen.
Darktrace has proven its value to us on multiple occasions. The same day that one of our clinic managers installed a new file transfer protocol, Darktrace identified traffic going out over an unencrypted port. With its visibility and understanding of our cyber landscape, Darktrace detected this abnormal action and responded at machine-speed. It protected us from exposing personal patient data.
Another time, Darktrace noticed someone on our guest network running a network snooping tool, triggering us to remove their computer from the network. While it was only on our guest network, the threat actor could have been targeting the patients that were using it. Darktrace protected them, helping us live up to our goal of serving our guests with compassion and respect.
Keeping our organization healthy
We do not have a large enough IT staff to constantly monitor all traffic across our digital estate, so Darktrace supplements and augments our team. The AI continuously monitors our cyber landscape and responds to attacks without disrupting our normal digital activities. Moreover, it works at all times of the day, even when I am not online. By handling the maintenance of our security, Darktrace buys my team time to work on other projects.
The cyber security of our organization is crucial for the safety of our patients and practitioners. Since deploying Darktrace, my team feels reassured that our security posture can handle any attacks that come our way. Darktrace is a valuable tool in our security stack.
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Sean Simpson
Executive Director of IT, Cullman Regional Medical Center (Guest Contributor)
Patch and Persist: Darktrace’s Detection of Blind Eagle (APT-C-36)
Since 2018, Blind Eagle has targeted Latin American organizations using phishing and RATs. Darktrace detected Blind Eagle activity on a customer network involving C2 connectivity, malicious payload downloads and data exfiltration. Without Autonomous Response, the attack escalated, highlighting the need for proactive detection and response defense to counter fast-evolving threats.
Customer Case Study: Leading Petrochemical Manufacturer
An industry leading petrochemical manufacturer uses the Darktrace ActiveAI Security Platform to improve visibility, protect against supply chain attacks, and save the security team hundreds of hours of incident investigation.
Tracking CVE-2025-31324: Darktrace’s detection of SAP Netweaver exploitation before and after disclosure
A critical SAP vulnerability, CVE-2025-31324, allows unauthenticated remote code execution via NetWeaver Visual Composer. Despite early mitigation guidance, many systems remain exposed. Darktrace detected exploitation attempts six days before public disclosure, highlighting the importance of proactive, threat-agnostic detection.
Pre-CVE Threat Detection: 8 Examples Identifying Malicious Activity Prior to Public Disclosure of a Vulnerability
Can you detect cyber threats before the world knows about them?
Every year, tens of thousands of Common Vulnerabilities and Exposures (CVEs) are disclosed, over 40,000 in 2024 alone [1], and a predicted higher number for 2025 by the Forum for Incident Response and Security Teams (FIRST).
However, cybercriminals don't wait for disclosure. They exploit zero-days while defenders remain in the dark.
Traditional, signature-based tools struggle to detect these early-stage threats. That’s why anomaly detection is becoming essential for organizations seeking pre-CVE detection.
Understanding the gap between zero-day attacks and public CVE disclosure
When a vulnerability is discovered, the standard practice is to report it to the vendor or the responsible organization, allowing them to develop and distribute a patch or fix before the details are made public. This is known as responsible disclosure.
The gap between exploitation of a zero-day and the disclosure of the vulnerability can sometimes be considerable, and retroactively attempting to identify successful exploitation on your network can be challenging, particularly if taking a signature-based approach.
However, abnormal behaviors in networks or systems, such as unusual login patterns or data transfers, can indicate attempted cyber-attacks, insider threats, or compromised systems.
Detecting threats without relying on CVE disclosure
Since Darktrace does not rely on rules or signatures, it can detect malicious activity that is anomalous even without full context of the specific device or asset in question.
For example, during the Fortinet exploitation late last year, the Darktrace Threat Research team were investigating a different Fortinet vulnerability, namely CVE 2024-23113, for exploitation when Mandiant released a security advisory around CVE 2024-47575, which aligned closely with Darktrace’s findings.
Retrospective analysis like this is used by Darktrace’s threat researchers to better understand detections across the threat landscape and to add additional context.
Below are eight examples from the past year where Darktrace detected malicious activity days or even weeks before a vulnerability was publicly disclosed.
Trends in pre-cve exploitation
The attack vs. patch race
In many cases, the disclosure of an exploited vulnerability can be off the back of an incident response investigation related to a compromise by an advanced threat actor using a zero-day. Once the vulnerability is registered and publicly disclosed as having been exploited, it can kick off a race between the attacker and defender.
Skilled nation-state actors
Nation-state actors, highly skilled with significant resources, are known to use a range of capabilities to achieve their target, including zero-day use. Often, pre-CVE activity is “low and slow”, last for months with high operational security.
After CVE disclosure, the barriers to entry lower, allowing less skilled and less resourced attackers, like some ransomware gangs, to exploit the vulnerability and cause harm. This is why two distinct types of activity are often seen: pre and post disclosure of an exploited vulnerability.
Examples of exploitation
Darktrace saw this consistent story line play out during several of the Fortinet and PAN OS threat actor campaigns highlighted above last year, where nation-state actors were seen exploiting vulnerabilities first, followed by ransomware gangs impacting organizations [2].
The same applies with the recent SAP Netweaver exploitations being tied to a China based threat actor earlier this spring with subsequent ransomware incidents being observed [3].
You spotted the anomaly but did you stop the breach?
Anomaly-based detection offers the benefit of identifying malicious activity even before a CVE is disclosed; however, security teams still need to quickly contain and isolate the activity.
For example, during the Ivanti chaining exploitation in the early part of 2025, a customer had Darktrace’s Autonomous Response capability enabled on their network. As a result, Darktrace was able to contain the compromise and shut down any ongoing suspicious connectivity by blocking internal connections and enforcing a “pattern of life” on the affected device.
This pre-CVE detection and response by Darktrace occurred 11 days before any public disclosure, demonstrating the value of an anomaly-based approach.
In some cases, customers have even reported that Darktrace stopped malicious exploitation of devices several days before a public disclosure of a vulnerability.
For example, During the ConnectWise exploitation, a customer informed the team that Darktrace had detected malicious software being installed via remote access. Upon further investigation, four servers were found to be impacted, while Autonomous Response had blocked outbound connections and enforced patterns of life on impacted devices.
Conclusion
By continuously analyzing behavioral patterns, systems can spot unusual activities and patterns from users, systems, and networks to detect anomalies that could signify a security breach.
Through ongoing monitoring and learning from these behaviors, anomaly-based security systems can detect threats that traditional signature-based solutions might miss, while also providing detailed insights into threat tactics, techniques, and procedures (TTPs). This type of behavioral intelligence supports pre-CVE detection, allows for a more adaptive security posture, and enables systems to evolve with the ever-changing threat landscape.
Credit to Nathaniel Jones (VP, Security & AI Strategy, Field CISO), Emma Fougler (Global Threat Research Operations Lead), Ryan Traill (Analyst Content Lead)
Patch and Persist: Darktrace’s Detection of Blind Eagle (APT-C-36)
What is Blind Eagle?
Since 2018, APT-C-36, also known as Blind Eagle, has been observed performing cyber-attacks targeting various sectors across multiple countries in Latin America, with a particular focus on Colombian organizations.
Blind Eagle characteristically targets government institutions, financial organizations, and critical infrastructure [1][2].
Attacks carried out by Blind Eagle actors typically start with a phishing email and the group have been observed utilizing various Remote Access Trojans (RAT) variants, which often have in-built methods for hiding command-and-control (C2) traffic from detection [3].
What we know about Blind Eagle from a recent campaign
Since November 2024, Blind Eagle actors have been conducting an ongoing campaign targeting Colombian organizations [1].
In this campaign, threat actors have been observed using phishing emails to deliver malicious URL links to targeted recipients, similar to the way threat actors have previously been observed exploiting CVE-2024-43451, a vulnerability in Microsoft Windows that allows the disclosure of a user’s NTLMv2 password hash upon minimal interaction with a malicious file [4].
Despite Microsoft patching this vulnerability in November 2024 [1][4], Blind Eagle actors have continued to exploit the minimal interaction mechanism, though no longer with the intent of harvesting NTLMv2 password hashes. Instead, phishing emails are sent to targets containing a malicious URL which, when clicked, initiates the download of a malicious file. This file is then triggered by minimal user interaction.
Clicking on the file triggers a WebDAV request, with a connection being made over HTTP port 80 using the user agent ‘Microsoft-WebDAV-MiniRedir/10.0.19044’. WebDAV is a transmission protocol which allows files or complete directories to be made available through the internet, and to be transmitted to devices [5]. The next stage payload is then downloaded via another WebDAV request and malware is executed on the target device.
Attackers are notified when a recipient downloads the malicious files they send, providing an insight into potential targets [1].
Darktrace’s coverage of Blind Eagle
In late February 2025, Darktrace observed activity assessed with medium confidence to be associated with Blind Eagle on the network of a customer in Colombia.
Within a period of just five hours, Darktrace / NETWORK detected a device being redirected through a rare external location, downloading multiple executable files, and ultimately exfiltrating data from the customer’s environment.
Since the customer did not have Darktrace’s Autonomous Response capability enabled on their network, no actions were taken to contain the compromise, allowing it to escalate until the customer’s security team responded to the alerts provided by Darktrace.
Darktrace observed a device on the customer’s network being directed over HTTP to a rare external IP, namely 62[.]60[.]226[.]112, which had never previously been seen in this customer’s environment and was geolocated in Germany. Multiple open-source intelligence (OSINT) providers have since linked this endpoint with phishing and malware campaigns [9].
The device then proceeded to download the executable file hxxp://62[.]60[.]226[.]112/file/3601_2042.exe.
Figure 1: Darktrace’s detection of the affected device connecting to an unusual location based in Germany.
Figure 2: Darktrace’s detection of the affected device downloading an executable file from the suspicious endpoint.
The device was then observed making unusual connections to the rare endpoint 21ene.ip-ddns[.]com and performing unusual external data activity.
This dynamic DNS endpoint allows a device to access an endpoint using a domain name in place of a changing IP address. Dynamic DNS services ensure the DNS record of a domain name is automatically updated when the IP address changes. As such, malicious actors can use these services and endpoints to dynamically establish connections to C2 infrastructure [6].
Further investigation into this dynamic endpoint using OSINT revealed multiple associations with previous likely Blind Eagle compromises, as well as Remcos malware, a RAT commonly deployed via phishing campaigns [7][8][10].
Figure 3: Darktrace’s detection of the affected device connecting to the suspicious dynamic DNS endpoint, 21ene.ip-ddns[.]com.
Shortly after this, Darktrace observed the user agent ‘Microsoft-WebDAV-MiniRedir/10.0.19045’, indicating usage of the aforementioned transmission protocol WebDAV. The device was subsequently observed connected to an endpoint associated with Github and downloading data, suggesting that the device was retrieving a malicious tool or payload. The device then began to communicate to the malicious endpoint diciembrenotasenclub[.]longmusic[.]com over the new TCP port 1512 [11].
Around this time, the device was also observed uploading data to the endpoints 21ene.ip-ddns[.]com and diciembrenotasenclub[.]longmusic[.]com, with transfers of 60 MiB and 5.6 MiB observed respectively.
Figure 4: UI graph showing external data transfer activity.
This chain of activity triggered an Enhanced Monitoring model alert in Darktrace / NETWORK. These high-priority model alerts are designed to trigger in response to higher fidelity indicators of compromise (IoCs), suggesting that a device is performing activity consistent with a compromise.
Figure 5: Darktrace’s detection of initial attack chain activity.
A second Enhanced Monitoring model was also triggered by this device following the download of the aforementioned executable file (hxxp://62[.]60[.]226[.]112/file/3601_2042.exe) and the observed increase in C2 activity.
Following this activity, Darktrace continued to observe the device beaconing to the 21ene.ip-ddns[.]com endpoint.
Darktrace’s Cyber AI Analyst was able to correlate each of the individual detections involved in this compromise, identifying them as part of a broader incident that encompassed C2 connectivity, suspicious downloads, and external data transfers.
Figure 6: Cyber AI Analyst’s investigation into the activity observed on the affected device.
Figure 7: Cyber AI Analyst’s detection of the affected device’s broader connectivity throughout the course of the attack.
As the affected customer did not have Darktrace’s Autonomous Response configured at the time, the attack was able to progress unabated. Had Darktrace been properly enabled, it would have been able to take a number of actions to halt the escalation of the attack.
For example, the unusual beaconing connections and the download of an unexpected file from an uncommon location would have been shut down by blocking the device from making external connections to the relevant destinations.
Conclusion
The persistence of Blind Eagle and ability to adapt its tactics, even after patches were released, and the speed at which the group were able to continue using pre-established TTPs highlights that timely vulnerability management and patch application, while essential, is not a standalone defense.
Organizations must adopt security solutions that use anomaly-based detection to identify emerging and adapting threats by recognizing deviations in user or device behavior that may indicate malicious activity. Complementing this with an autonomous decision maker that can identify, connect, and contain compromise-like activity is crucial for safeguarding organizational networks against constantly evolving and sophisticated threat actors.
Credit to Charlotte Thompson (Senior Cyber Analyst), Eugene Chua (Principal Cyber Analyst) and Ryan Traill (Analyst Content Lead)
Appendices
IoCs
IoC – Type - Confidence Microsoft-WebDAV-MiniRedir/10.0.19045 – User Agent
62[.]60[.]226[.]112 – IP – Medium Confidence
hxxp://62[.]60[.]226[.]112/file/3601_2042.exe – Payload Download – Medium Confidence
21ene.ip-ddns[.]com – Dynamic DNS Endpoint – Medium Confidence
diciembrenotasenclub[.]longmusic[.]com - Hostname – Medium Confidence
Darktrace’s model alert coverage
Anomalous File / Suspicious HTTP Redirect Anomalous File / EXE from Rare External Location Anomalous File / Multiple EXE from Rare External Location Anomalous Server Activity / Outgoing from Server Unusual Activity / Unusual External Data to New Endpoint Device / Anomalous Github Download Anomalous Connection / Multiple Connections to New External TCP Port Device / Initial Attack Chain Activity Anomalous Server Activity / Rare External from Server Compromise / Suspicious File and C2 Compromise / Fast Beaconing to DGA Compromise / Large Number of Suspicious Failed Connections Device / Large Number of Model Alert
Mitre Attack Mapping:
Tactic – Technique – Technique Name
Initial Access - T1189 – Drive-by Compromise Initial Access - T1190 – Exploit Public-Facing Application Initial Access ICS - T0862 – Supply Chain Compromise Initial Access ICS - T0865 – Spearphishing Attachment Initial Access ICS - T0817 - Drive-by Compromise Resource Development - T1588.001 – Malware Lateral Movement ICS - T0843 – Program Download Command and Control - T1105 - Ingress Tool Transfer Command and Control - T1095 – Non-Application Layer Protocol Command and Control - T1571 – Non-Standard Port Command and Control - T1568.002 – Domain Generation Algorithms Command and Control ICS - T0869 – Standard Application Layer Protocol Evasion ICS - T0849 – Masquerading Exfiltration - T1041 – Exfiltration Over C2 Channel Exfiltration - T1567.002 – Exfiltration to Cloud Storage