MEDJACK.3 Poses a Threat to Hospital Devices
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
MEDJACK.3 is designed to steal patient’s data by deploying an old malware spreader to redirect the attack towards devices on Windows XP, Windows Server 2003 as well as Windows 2008 and 2012. It exploits a vulnerability in the Windows Server service (svchost.exe), allowing attackers to use C2 servers for a backdoor within a PACS image viewer. Additionally MEDJACK.3 has anti-detection capabilities that make it lie dormant during sandboxing.
More information is due to be released about MEDJACK.3 shortly.
Remediation steps
Last edited: 17 February 2020 11:34 am