Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

Brinztech Alert: Pear Ransomware Group Targets Healthcare Entity In Data Extortion Campaign

Card image cap

Brinztech https://brinztech.com/breach-alerts/

News / Incident Analysis

The threat actor collective known as PEAR (Pure Extraction And Ransom) has initiated a high-severity cyber extortion campaign targeting the healthcare sector in Texas. Unlike traditional ransomware operations that rely heavily on disruptive file-encryption payloads to halt operations, the PEAR group specializes in a “data-theft-only” model.

Threat intelligence monitoring indicates that the attackers gained unauthorized access to internal network infrastructure—reportedly abusing legitimate remote monitoring and management (RMM) utilities like AteraAgent for persistence and lateral movement. Rather than deploying lockers or binaries to scramble system files, the group focused strictly on staging and exfiltrating gigabytes of sensitive files. They have subsequently published countdown timers on their dark web leak sites to pressure the organization into meeting monetary ransom demands under threat of public disclosure.

Key Cybersecurity Insights

The PEAR group’s methodology highlights several critical evolutionary shifts in modern cybercrime and healthcare targeting:

  • The Rise of Pure Extortion (Data-Theft-Only): By avoiding encryption, threat actors bypass many traditional endpoint detection rules designed to catch file-locking behavior. It also reduces operational friction for the attackers while maximizing psychological and regulatory pressure on victims through the threat of releasing Protected Health Information (PHI).
  • Abuse of Legitimate Administrative Tools (LotL): The integration of tools like AteraAgent illustrates “Living off the Land” (LotL) tactics. By leveraging legitimate RMM software already trusted or overlooked by enterprise security baselines, attackers blend malicious remote administration directly into normal administrative traffic.
  • Severe Downstream Compliance and Patient Risks: Healthcare clinics and regional medical providers maintain dense repositories of Personally Identifiable Information (PII), medical histories, insurance data, and employee records, making them high-yield targets for extortion syndicates aiming to trigger strict HIPAA violations.

Mitigation Strategies

Healthcare providers and network administrators must adapt their defense-in-depth strategies to counter non-encryption exfiltration campaigns:

  • RMM and Dual-Use Tool Auditing: Continuously audit network environments for unauthorized or unmanaged Remote Monitoring and Management agents (such as Atera, AnyDesk, TeamViewer, or ConnectWise). Enforce strict allowlisting for administrative utilities.
  • Egress Monitoring and Data Loss Prevention (DLP): Tune security information and event management (SIEM) and network detection and response (NDR) tools to flag anomalous outbound data volumes, unexpected spikes in cloud storage transfers, or unusual connections to Tor infrastructure.
  • Incident Response Alignment: Update corporate incident response playbooks to explicitly address non-encryption extortion scenarios, ensuring that containment procedures prioritize isolating compromised credentials and cutting off data staging paths even if system availability remains intact.

Secure Your Organization with Brinztech

As a cybersecurity provider, we can protect your business from the threats discussed here. Contact us to learn more about our services.

Questions or Feedback?

For expert advice, use our ‘Ask an Analyst’ feature. Brinztech does not warrant the validity of external claims. For general inquiries or to report this post, please email us: contact@brinztech.com

The post Brinztech Alert: PEAR Ransomware Group Targets Healthcare Entity in Data Extortion Campaign first appeared on Brinztech.