NailaoLocker ransomware targeted European healthcare organizations between June and October 2024.
The malware campaign, called The Green Nailao, involved the use of ShadowPad, PlugX, and the newly discovered NailaoLocker ransomware.
The attack exploited a zero-day vulnerability in Check Point VPN appliances, allowing the threat actors to access sensitive information and move laterally through the network.
Although the campaign shares similarities with China-linked APT groups, attribution remains uncertain.