Skip to main content

MEDJACK.3 Poses a Threat to Hospital Devices

A third version of the “medical device hijack” malware has been discovered. It can target the PACS (Picture Archiving and Communication System) image viewer of medical devices in X-ray machines, MRI and CT Scanners.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A third version of the “medical device hijack” malware has been discovered. It can target the PACS (Picture Archiving and Communication System) image viewer of medical devices in X-ray machines, MRI and CT Scanners.

Threat details

MEDJACK.3 is designed to steal patient’s data by deploying an old malware spreader to redirect the attack towards devices on Windows XP, Windows Server 2003 as well as Windows 2008 and 2012. It exploits a vulnerability in the Windows Server service (svchost.exe), allowing attackers to use C2 servers for a backdoor within a PACS image viewer. Additionally MEDJACK.3 has anti-detection capabilities that make it lie dormant during sandboxing.

More information is due to be released about MEDJACK.3 shortly.


Remediation steps

Type Step
  • Ensure all devices are running on the latest operating systems and the latest patches are applied.
  • Multiple backups from PACS should be created including at least one off-network backup (e.g. to tape).

Last edited: 17 February 2020 11:34 am