Back to Intelligence

WALLSTREET Ransomware Gang: 4 New Leak-Site Claims Posted — Healthcare & Manufacturing Targeting Analysis with Detection Rules

SA
Security Arsenal Team
October 3, 2026
11 min read

Classification: TLP:CLEAR | Publication Date: 2026-10-03 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims

Executive Summary

Monitoring of the WALLSTREET ransomware group's dark web leak site shows four new listings published between 2026-09-29 and 2026-10-03. WALLSTREET claims to have compromised the following organizations:

  • St. Francis Healthcare Systems of Hawaii (Healthcare, US) — listed 2026-10-03
  • World Cup 2034 (Other, SA) — listed 2026-10-03
  • Tronex A/S (Manufacturing, DK) — listed 2026-10-02
  • Gibson Area Hospital & Health Services (Healthcare, US) — listed 2026-09-29

Half of the claimed victims in this batch are healthcare providers, and all four listings appeared within a five-day window, suggesting an active campaign pulse. Enterprise defenders in healthcare, manufacturing, and large-scale event/logistics operations should treat this as a prompt to validate perimeter exposure, review the CVEs WALLSTREET is known to exploit, and deploy the detection content in this briefing.

Every listing above is an unverified accusation by a criminal actor. Inclusion on a leak site is not confirmation of a breach.

Sourcing & Verification

  • 3 of 4 listings (St. Francis Healthcare Systems of Hawaii, World Cup 2034, Tronex A/S) were independently observed by a second leak-site crawler, meaning two separate monitoring sources saw WALLSTREET publish the claim.
  • 1 of 4 listings (Gibson Area Hospital & Health Services) appears on a single source only — ransomware.live — with no second-crawler confirmation that the posting even exists.
  • Multi-source corroboration confirms only that the gang made the claim. It does NOT confirm a breach occurred. No tier in our data confirms a breach — only the named organization or its regulator can do that.
  • A named organization may dispute a listing, and a denial is likewise not proof the claim is false. Disclosure obligations vary by jurisdiction and sector, and not every incident is reportable — neither silence nor denial settles the question.
  • Security Arsenal will publish corrections as warranted and welcomes contact from any named organization at security@securityarsenal.com.

Threat Actor Profile — WALLSTREET

AttributeAssessment
AliasesNo widely documented aliases; the "WALLSTREET" branding appears consistent across its leak-site presence
Operating modelAssessed as a Ransomware-as-a-Service (RaaS) operation with affiliates conducting intrusions and the core team managing the leak site and negotiation infrastructure
Ransom demandsTypically scaled to victim revenue; demands in observed campaigns range from low six figures to multi-million USD equivalents in cryptocurrency
Initial access methodsExploitation of internet-facing remote services (VPN concentrators, RDP, firewall management interfaces), spear-phishing with malicious attachments, and purchased access from initial access brokers (IABs)
Extortion modelDouble extortion — data exfiltration prior to encryption, with leak-site publication used as pressure against non-payers
Dwell timeObserved dwell time ranges from days to roughly two weeks between initial access and detonation, with exfiltration typically staged in the final 48–72 hours

WALLSTREET follows the modern post-2023 ransomware playbook: quiet ingress via edge-device exploitation, credential harvesting, lateral movement via legitimate admin tooling (living-off-the-land), bulk data staging to attacker-controlled cloud storage, then mass encryption during off-hours.

Current Campaign Analysis

Sector Targeting

  • Healthcare (2 of 4 listings): St. Francis Healthcare Systems of Hawaii (US) and Gibson Area Hospital & Health Services (US). Healthcare remains a high-pressure extortion target due to patient-safety sensitivity and regulatory exposure. Note that the Gibson Area Hospital listing is single-source only.
  • Manufacturing (1 of 4): Tronex A/S (DK). Manufacturing victims typically face operational-technology downtime pressure.
  • Other (1 of 4): World Cup 2034 (SA) — a high-profile, deadline-driven target where reputational and schedule pressure may be the extortion lever.

Geographic Concentration

The US accounts for 2 of 4 listings, with single listings in Saudi Arabia and Denmark. This is consistent with a gang that pursues opportunity over geography, but the US healthcare weighting is notable.

Victim Profile

The claimed victims skew toward mid-size regional organizations (community hospital systems, a mid-market manufacturer) alongside one large, internationally visible entity. This mixed profile is typical of affiliate-driven RaaS operations: affiliates hit what their access allows, not a curated target list.

Posting Frequency & Escalation

Four listings in five days (2026-09-29 → 2026-10-03), including two on the same day, indicates a campaign pulse rather than baseline trickle. Watch for a follow-on wave: gangs often batch-publish after a negotiation deadline expires.

CVE Exposure — Hypothesis Only

We have no evidence tying any specific CVE to any specific named listing above. However, WALLSTREET's known tradecraft — edge-device and remote-access exploitation — aligns with several vulnerabilities currently on the CISA Known Exploited Vulnerabilities catalog with confirmed ransomware use. Organizations in the targeted sectors should treat the following as priority patch/verify items:

  • CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1). Directly relevant to VPN-gate initial access.
  • CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password. Management-plane compromise enables full network visibility and policy manipulation.
  • CVE-2026-59310 — VMware vCenter path traversal. vCenter compromise is a force multiplier for mass encryption of virtualized estates.
  • CVE-2026-63077 — JetBrains TeamCity deserialization. CI/CD compromise enables supply-chain-style payload delivery and credential theft.
  • CVE-2026-48027 — Nx Console embedded malicious code. Developer-workstation ingress via compromised tooling.

Detection Engineering

The following content targets WALLSTREET's known TTPs: edge/VPN exploitation, phishing-driven execution, lateral movement via PsExec/WMI, and pre-encryption data staging.

YAML
---
title: WALLSTREET Ransomware - PsExec Service Creation for Lateral Movement
id: 9f3a1c2e-7b4d-4e1a-a5f6-2c8d9e0b1a34
status: experimental
description: Detects PsExec-style remote service creation consistent with WALLSTREET affiliate lateral movement tradecraft
author: Security Arsenal Threat Intel
logsource:
  category: service_creation
  product: windows
detection:
  selection_psexec:
    ServiceName:
      - 'PSEXESVC'
      - 'PAExec*'
      - 'RemComSvc'
  selection_generic_admin:
    ImagePath|contains:
      - '\\ADMIN$\\'
      - '\\IPC$\\'
  condition: selection_psexec or selection_generic_admin
falsepositives:
  - Legitimate administrative remote management tools
level: high
date: 2026/10/03
tags:
  - attack.lateral_movement
  - attack.t1021.002
  - attack.t1569.002
---
title: WALLSTREET Ransomware - Data Staging via Rclone or Archiving Before Exfiltration
id: 4b7e2d1f-3a9c-4f8b-b2e1-6d5c7a8f9e01
status: experimental
description: Detects use of rclone, 7zip/rar mass archiving, or suspicious cloud sync tools associated with pre-encryption data staging observed in WALLSTREET campaigns
author: Security Arsenal Threat Intel
logsource:
  category: process_creation
  product: windows
detection:
  selection_rclone:
    Image|endswith:
      - '\\rclone.exe'
    CommandLine|contains:
      - 'copy'
      - 'sync'
      - 'move'
  selection_archive:
    Image|endswith:
      - '\\7z.exe'
      - '\\rar.exe'
      - '\\winrar.exe'
    CommandLine|contains:
      - ' a '
      - '-p'
  selection_renamed:
    CommandLine|contains:
      - '--config'
      - 'mega'
      - 'dropbox'
      - 'gdrive'
  condition: selection_rclone or selection_archive or selection_renamed
falsepositives:
  - Legitimate backup or file synchronization operations
level: high
date: 2026/10/03
tags:
  - attack.collection
  - attack.t1560.001
  - attack.exfiltration
  - attack.t1567.002
---
title: WALLSTREET Ransomware - VPN Edge Exploitation Followed by Anomalous Authentication
id: 7c1d5e9a-2f4b-4a6c-8d3e-1b9a7c5f3e28
status: experimental
description: Detects successful VPN authentication from unusual geographies or TOR/hosting ASNs shortly after edge-device scanning or exploit attempts - WALLSTREET initial access pattern
author: Security Arsenal Threat Intel
logsource:
  category: authentication
  product: firewall
detection:
  selection_success:
    action: 'success'
    service:
      - 'vpn'
      - 'sslvpn'
      - 'ikev1'
      - 'ikev2'
  filter_internal:
    src_ip|cidr:
      - '10.0.0.0/8'
      - '172.16.0.0/12'
      - '192.168.0.0/16'
  condition: selection_success and not filter_internal
timeframe: 15m
falsepositives:
  - Traveling employees, legitimate remote users on residential ISPs
level: medium
date: 2026/10/03
tags:
  - attack.initial_access
  - attack.t1133
  - attack.t1190

The following KQL query for Microsoft Sentinel hunts pre-ransomware staging behavior: compressed archive creation on servers followed by high-volume outbound transfers within a 6-hour window.

KQL — Microsoft Sentinel / Defender
// WALLSTREET pre-encryption staging hunt: mass archiving + outbound exfil within 6h
let Archiving =
    DeviceProcessEvents
    | where TimeGenerated > ago(7d)
    | where FileName in~ ("7z.exe", "rar.exe", "winrar.exe", "rclone.exe")
       or ProcessCommandLine has_any ("rclone copy", "rclone sync", " a -p", "-mx9")
    | summarize ArchiveCommands = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
                Commands = make_set(ProcessCommandLine, 10) by DeviceName, AccountName;
let Outbound =
    DeviceNetworkEvents
    | where TimeGenerated > ago(7d)
    | where RemoteIPType == "Public"
    | where RemotePort in (443, 22, 21, 990) or RemoteUrl has_any ("mega.nz", "dropbox", "drive.google", "file.io", "transfer.sh")
    | summarize Connections = count(), RemoteIPs = make_set(RemoteIP, 20), RemoteURLs = make_set(RemoteUrl, 20)
      by DeviceName, bin(TimeGenerated, 1h);
Archiving
| join kind=inner (Outbound) on DeviceName
| where TimeGenerated between (FirstSeen .. datetime_add("hour", 6, FirstSeen))
| project DeviceName, AccountName, FirstSeen, LastSeen, ArchiveCommands, Connections, RemoteIPs, RemoteURLs, Commands
| order by FirstSeen desc;

The following PowerShell script performs rapid-response checks: exposed RDP listeners, scheduled tasks created in the last 7 days, and Volume Shadow Copy tampering — three of the highest-signal pre/post-intrusion artifacts for this playbook.

PowerShell
# Security Arsenal - WALLSTREET Rapid Triage Script (run elevated)
# Checks: RDP exposure, recent scheduled tasks, shadow copy tampering

Write-Host "=== [1] RDP Exposure Check ===" -ForegroundColor Cyan
$rdp = Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue
if ($rdp) {
    Write-Host "WARNING: RDP listening on 3389." -ForegroundColor Red
    $rdpEnabled = (Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server').fDenyTSConnections
    $nla = (Get-ItemProperty 'HKLM:\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -ErrorAction SilentlyContinue).UserAuthentication
    Write-Host "  fDenyTSConnections=$rdpEnabled (0=RDP enabled) | NLA=$nla (1=NLA on)"
    Get-NetFirewallRule -DisplayGroup "Remote Desktop" -ErrorAction SilentlyContinue |
        Where-Object Enabled -eq 'True' | Select-Object DisplayName, Profile | Format-Table
} else { Write-Host "OK: No RDP listener on 3389." -ForegroundColor Green }

Write-Host "=== [2] Scheduled Tasks Created/Modified in Last 7 Days ===" -ForegroundColor Cyan
$cutoff = (Get-Date).AddDays(-7)
Get-ScheduledTask | ForEach-Object {
    $info = $_ | Get-ScheduledTaskInfo -ErrorAction SilentlyContinue
    if ($info -and $info.LastRunTime -gt $cutoff) {
        [PSCustomObject]@{ TaskName=$_.TaskName; Path=$_.TaskPath; LastRun=$info.LastRunTime; Author=$_.Author }
    }
} | Where-Object { $_.Path -notlike "\Microsoft*" } | Sort-Object LastRun -Descending | Format-Table -AutoSize

Write-Host "=== [3] Volume Shadow Copy Status ===" -ForegroundColor Cyan
$shadows = Get-WmiObject Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) {
    $shadows | Select-Object DeviceObject, InstallDate, VolumeName | Format-Table
} else {
    Write-Host "ALERT: No shadow copies present. 'vssadmin delete shadows' is a hallmark pre-encryption action." -ForegroundColor Red
}

Write-Host "=== [4] Recent vssadmin/bcdedit/wbadmin Tampering in Event Log ===" -ForegroundColor Cyan
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688; StartTime=$cutoff} -ErrorAction SilentlyContinue |
    Where-Object { $_.Message -match 'vssadmin.*delete|bcdedit.*recoveryenabled|wbadmin.*delete' } |
    Select-Object TimeCreated, Message -First 20 | Format-List

Write-Host "Triage complete. Escalate any ALERT/WARNING findings to IR immediately." -ForegroundColor Cyan

Incident Response Priorities

T-Minus Detection Checklist (Before Encryption Fires)

  1. New or renamed admin tooling — PsExec, rclone, AnyDesk, ScreenConnect, or ngrok appearing on servers where they were never baselined.
  2. Mass archiving activity — 7z/rar jobs touching file shares, especially with password flags (-p).
  3. Shadow copy deletion — vssadmin delete shadows, bcdedit recovery-disabled changes, wbadmin delete catalog.
  4. Anomalous VPN/edge authentication — successful logins from unfamiliar ASNs, TOR exits, or geographies inconsistent with the user base, particularly after edge-device patch windows were missed.
  5. EDR tampering — service stops, uninstall attempts, or exclusion additions on security tooling.
  6. Off-hours Kerberos/service anomalies — DCSync-style replication requests or golden-ticket indicators.

Assets WALLSTREET Historically Prioritizes for Exfiltration

  • HR records, payroll, and PII/PHI databases (maximum regulatory leverage, especially against healthcare targets)
  • Financial statements, contracts, and legal correspondence
  • Email archives of executive and legal mailboxes
  • Backup catalogs and disaster-recovery configurations (to sabotage recovery)
  • For manufacturing: engineering drawings and IP repositories

Containment Actions — Ordered by Urgency

  1. Isolate affected segments immediately — disable switch ports / NAC-quarantine rather than powering off (preserve memory for forensics).
  2. Disable compromised accounts and force enterprise-wide credential resets, prioritizing domain admins, service accounts, and VPN users.
  3. Block known exfil destinations at the egress proxy/firewall (consumer cloud storage, file-transfer services not in business use).
  4. Snapshot and preserve evidence — firewall/VPN logs, EDR telemetry, and memory images before any remediation wipes them.
  5. Verify backup integrity offline before declaring recovery readiness; assume the attacker enumerated backup infrastructure.
  6. Engage counsel early on regulatory notification analysis — but remember: a leak-site claim alone is not proof a reportable incident occurred. Verify forensically.

Hardening Recommendations

Immediate (24 Hours)

  • Patch or mitigate the KEV edge-device CVEs: CVE-2026-50751 (Check Point IKEv1), CVE-2026-20316 (Cisco FMC), CVE-2026-59310 (vCenter). If patching isn't possible in 24h, apply vendor workarounds and restrict management interfaces to jump-host-only access.
  • Enforce phishing-resistant MFA (FIDO2/passkeys) on all remote access — VPN, RDP gateways, and webmail.
  • Disable IKEv1 aggressive mode where legacy Check Point configurations remain.
  • Block PsExec/rclone/AnyDesk execution via AppLocker/WDAC where not explicitly approved; alert on any execution.
  • Enable tamper protection on EDR and alert on any shadow-copy deletion command.

Short-Term (2 Weeks)

  • Segment identity from infrastructure: dedicated Privileged Access Workstations, tiered administration, and no domain-admin logons to general-purpose servers or workstations.
  • Egress filtering by default: deny outbound 443 to uncategorized destinations; force all web traffic through authenticated proxy with TLS inspection where legally permissible.
  • Immutable/offline backups with at least one copy unreachable from production identity (separate credentials, separate blast radius). Test restoration — not just backup success.
  • CI/CD isolation: given exposure like CVE-2026-63077 (TeamCity) and CVE-2026-48027 (Nx Console), segment build infrastructure from production and require signed, verified dependencies.
  • Deploy the detection content above into your SIEM and validate with purple-team simulation of the staging-and-encrypt sequence.

This briefing is based on unverified threat-actor claims observed on criminal infrastructure. Security Arsenal does not assert that any named organization has suffered a breach. Named organizations are invited to contact security@securityarsenal.com.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.