← All actors

Daixin Team

Aliases: Daixin, Daixin Team ransomware

Source profile review date: 2026-06-01

Added to the source registry: 2022-08-03 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.

Executive summary

Daixin Team focuses, according to CISA/FBI/HHS, mainly on healthcare and public health, using VPN access, credential abuse, RDP/SSH, data exfiltration and ransomware.

Daixin Team is relevant for healthcare organisations because public advisories link the group to Healthcare and Public Health attacks with emphasis on remote access, compromised credentials, Rclone exfiltration and disruption of critical services.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Executive summary

    Daixin Team is a ransomware and data-extortion group that FBI, CISA and HHS say has mainly attacked US Healthcare and Public Health organisations. The profile matters because healthcare environments often combine high availability requirements, sensitive personal data, medical systems, supplier integrations and remote administration access.

    Daixin attacks are not only about encryption. The advisory describes data exfiltration, publication threats and use of tools such as Rclone. In healthcare, this creates immediate pressure on privacy, continuity and patient care.

    The concrete defensive lesson is that VPN, MFA, network segmentation, logging and backup isolation are not optional in healthcare environments.

    Group and development

    Daixin Team was described in the joint advisory as a cybercrime group actively targeting HPH organisations. This sector focus makes the profile different from many broad RaaS operations.

    The group uses both ransomware and data extortion. Defence must therefore keep systems available and prevent sensitive data from being collected or moved out. A backup does not solve the second problem.

    Daixin should be analysed through operational dependencies: which systems support patient care, which suppliers have access, which VPN profiles exist and where the most sensitive data is stored.

    Attack pattern from public cases

    The advisory describes use of VPN servers and compromised credentials. In some cases, access was obtained through VPN servers without MFA. Healthcare organisations with external access without strong MFA have a proven risk.

    After access, actors move laterally via RDP and SSH, search for sensitive data and prepare exfiltration. Rclone is named as a data-transfer tool, making detection of Rclone configuration, command lines and outbound connections important.

    Daixin ransomware can target specific file locations and systems. Healthcare environments must therefore know which servers support clinical processes and which segments must never be reachable directly from ordinary workstations or VPN routes.

    The attack is often a combination of identity and network path. A valid VPN account, lateral access and insufficient segmentation can cause damage faster than a standalone exploit.

    Known IOCs and artefacts

    Rclone is a concrete IOC category in the Daixin advisory. Look for rclone.exe, configuration files, cloud destinations, command lines and large outbound transfers.

    VPN access without MFA or with compromised credentials is a core initial-access indicator. Check login sources, account age, failed attempts, new devices and sessions outside normal hours.

    RDP and SSH activity between internal systems is relevant for lateral movement. In healthcare networks, these protocols must be tightly limited and logged.

    Victim pattern and lessons

    Daixin is mainly linked to Healthcare and Public Health. The lesson is that ransomware in healthcare is not a pure IT incident: disruption can affect appointments, diagnostics, medication processes, administration and patient communication.

    Because healthcare data is highly sensitive, data exfiltration is already serious by itself. Even without long downtime, an organisation can face notification duties, reputational damage and leadership pressure.

    Outside healthcare, Daixin remains useful as an example: remote access without MFA, insufficient segmentation and weak data monitoring are cross-sector risks.

    How to defend against Daixin Team

    Require MFA on VPN, administration portals and external access. Check exceptions and legacy accounts.

    Segment clinical systems, domain controllers, file servers and backup environments. A VPN account must not be able to move freely through the network.

    Monitor Rclone and similar exfiltration tools. Alert on large data transfers, new binaries, unknown cloud destinations and compression of patient or business data.

    Test recovery processes for critical healthcare systems and ensure backups are protected outside the ordinary domain.

    Practical detection logic for Daixin Team

    Daixin detection must start at VPN. The CISA/FBI/HHS advisory links the group to VPN access with compromised credentials and environments without MFA.

    Rclone is a concrete exfiltration indicator. Detect rclone.exe, configuration files, command lines with remote destinations, large outbound transfers and use from servers that normally do not transfer data externally.

    Because Daixin mainly affects HPH, detection should also consider critical healthcare processes: planning, records, diagnostics, medication and communication systems.

    Concrete hardening priorities

    Enforce MFA on VPN without exceptions for legacy or suppliers.

    Segment medical, administrative and management environments. A VPN user must not automatically reach file servers, backup consoles, EHR-related systems or domain controllers.

    Practise recovery by clinical priority: which systems return first, which data is needed and which administration accounts can be trusted after compromise?

    Identity, naming and attribution

    For Daixin Team, the operational starting point is an exact identity match. The local dossier records the following names or aliases: Daixin, Daixin Team ransomware. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    toolingRclone associated exfiltrationCISA AA22-294ADaixin advisory includes Rclone-associated IOCs.
    accessVPN access with compromised credentials / no MFACISA AA22-294AObserved route into HPH organizations.
    toolingRDP and SSH lateral movementCISA AA22-294AUsed for movement after initial access.
    sectorHealthcare and Public Health targetingCISA AA22-294APredominant sector focus in advisory.

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.