
New Ransomware-as-a-Service 'BlackVortex' Targets European Hospitals with Double Extortion Tactics
A new ransomware operation named 'BlackVortex' is emerging, focusing on European hospitals and utilizing double extortion techniques to maximize pressure on victims.
Encrygma is selling the entire Full Cyber Weapon Research of New Ransomware-as-a-Service 'BlackVortex' Targets European Hospitals with Double Extortion Tactics for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Europe
- Confidence:
- High Confidence
- CVE:
- CVE-2022-30190, CVE-2022-26809
- Source:
- CrowdStrike Research
- Read Time:
- 6 min
Executive Summary
As of June 2026, a new ransomware-as-a-service (RaaS) operation identified as 'BlackVortex' has gained significant traction in the cybercriminal underground. This operation is specifically targeting healthcare facilities across Europe, particularly hospitals, employing double extortion techniques. BlackVortex is not only encrypting data but also threatening to leak sensitive patient information to amplify the financial motivation for victims to comply with ransom demands.
Threat Analysis
BlackVortex appears to have been operational since early 2026, with its first known attack recorded in March. Initial analysis highlights a disturbing trend of heightened cyberattack activity against critical healthcare infrastructure, particularly in countries with high healthcare reliance on digital systems, such as Germany, France, and the UK. The operation is led by a group known as "Ciphered Hands," which has been linked to prior ransomware incidents and is believed to feature a professional lineup of malware developers and social engineers.
Victims have reported demands ranging from €500,000 to €2 million, placing significant operational pressure on targeted facilities, which often operate under tight financial conditions.
Double Extortion Technique
The double extortion model employed by BlackVortex involves two phases:
- Data Encryption - The malware encrypts files and locks users out of critical systems.
- Data Exfiltration - Before encryption, data is copied and stored on the attackers' servers. Following the attack, the group threatens to leak data containing sensitive medical records, employee information, and other critical data unless the ransom is paid. This dual-threat approach has led to heightened alarm among healthcare IT departments.
Technical Details
BlackVortex utilizes a modified version of the notorious Conti ransomware framework, with enhancements that allow for stealthy data exfiltration. The ransomware is spread through phishing emails containing malicious Word documents that exploit known vulnerabilities, particularly CVE-2022-30190 (Follina) and CVE-2022-26809.
Once installed, the ransomware employs a custom encryption algorithm that obfuscates file names and extensions to further complicate recovery efforts. Notably, the attackers utilize anonymous VPN and TOR networks to mask their locations, presenting a challenge for law enforcement.
Attribution Assessment
While attribution remains challenging, the operational techniques and infrastructure employed suggest a link to Eastern European cybercriminal groups, specifically targeting organizations in the Western European healthcare sector. The use of double extortion tactics and the involvement of previously identified group members from Conti contribute to a moderate confidence level in this assessment.
Implications
The rise of BlackVortex poses a significant threat not only in terms of immediate financial impact on affected hospitals but also in jeopardizing patient safety and privacy. A successfully executed ransomware attack could lead to disrupted services affecting patient care, potentially leading to life-threatening scenarios.
Moreover, the healthcare sector is already under scrutiny for data protection compliance, thus posing additional reputational risks for the victimized organizations that might face regulatory and legal repercussions for failing to protect sensitive patient data adequately.
Recommendations
Organizations in the healthcare sector should take immediate measures to bolster their cybersecurity posture:
- Implement Strong Email Filtering - Deploy advanced email filtering solutions to reduce phishing incidents.
- Regularly Update and Patch Systems - Ensure all systems are patched against known vulnerabilities.
- Employee Training - Conduct regular cybersecurity awareness training, focusing on identifying phishing and social engineering attacks.
- Incident Response Planning - Establish and regularly update an incident response plan tailored to ransomware attacks, including a data recovery strategy.
- Regular Backups - Maintain secure, offline backups to reduce reliance on ransom payments in case of an incident.
By adopting these proactive measures, healthcare organizations can enhance their resilience against growing ransomware threats such as those posed by BlackVortex.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chaos and M3rx Ransomware Groups Escalate Attacks on US Professional and Healthcare Sectors

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

