Skip to content
Signals
Monitoring NVD, CISA KEV, EPSS and the Dragons Community ransomware tracker in near-real timeMonitoring NVD, CISA KEV, EPSS and the Dragons Community ransomware tracker in near-real time
← Campaigns
ActiveTLP:AMBERConfidence: High

Operation BlackHarvest

First seen January 15, 2026 · Last seen May 20, 2026

Public preview

Summary and targeting visible. Pro adds TTP and actor context, Pro+ adds IOC exports and enrichment.

Plans →

Summary

Double-extortion ransomware campaign targeting healthcare and manufacturing organizations through initial access broker partnerships. Uses phishing and VPN credential abuse for entry.

Target Sectors

HealthcareManufacturing

Target Regions

North America

Safety Note

Fictional campaign. No real victim identifiers, ransom amounts or leak site data included.

Related CVEs

MITRE ATT&CK Techniques

T1566.001Spearphishing Attachment

Initial Access

Train users to identify phishing. Deploy email gateway filtering. Enable attachment sandboxing. Block macro execution by default.

T1486Data Encrypted for Impact

Impact

Maintain offline backups. Monitor for mass file modification events. Restrict execution of unknown binaries. Implement endpoint detection for encryption behavior.

T1078Valid Accounts

Persistence

Enforce MFA on all accounts. Monitor for impossible travel and unusual login patterns. Implement privileged access management. Review service account usage.

T1133External Remote Services

Initial Access

Enforce MFA on all remote access. Restrict VPN/RDP to allowlisted networks where possible. Monitor remote access logs for anomalies. Patch remote access infrastructure promptly.