LIVE
LATEST THREAT: Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure THREAT ALERT ACTIVE
Intelligence DB / Group Profile Arcus Media

Arcus Media: The RaaS Operation Targeting Healthcare and Critical Infrastructure

Arcus Media emerged in April 2024 as a Rust-based ransomware-as-a-service operation with a focus on healthcare, utilities, and critical infrastructure sectors. Despite a relatively low public profile, the group has claimed over 80 victims across 15 countries, operates a professional affiliate recruitment programme, and has been linked to credential theft campaigns targeting unpatched VPN appliances.

By Ransomware Tracker ·
Arcus MediaransomwareRaaShealthcarecritical infrastructureRustdouble extortionaffiliateVPN exploitation2026
Threat Level
8/10
Sectors Targeted
healthcare
utilities
manufacturing
critical-infrastructure
education
government
Ransomware Family
Arcus Media

Overview

Arcus Media is a ransomware-as-a-service operation that first appeared on underground forums in April 2024. The group launched with a Rust-based encryptor targeting both Windows and Linux (ESXi) environments, a dark web leak site, and a professional affiliate recruitment programme that offered unusually high revenue splits to attract experienced operators from competing RaaS platforms whose operations had been disrupted.

The group deliberately avoided the profile of some contemporaries: no aggressive public persona, no provocative leak site design, no open conflict with law enforcement or security researchers. This low-profile approach, combined with a selective targeting focus and consistent operational security, allowed Arcus Media to develop for over a year before receiving significant research coverage.

By mid-2026, the group had claimed over 80 victims on its data leak site — a figure believed to significantly undercount total victims, as many organisations pay without their breach being publicly disclosed. Victims span healthcare, utilities, manufacturing, education, and regional government entities across North America, Western Europe, and Australia.

Technical Profile

Encryptor: Arcus Media’s encryptor is written in Rust, following a trend established by other RaaS operations seeking stronger cross-platform capability and resistance to static analysis. The encryptor supports:

  • Windows x64 and x86 targets
  • Linux targeting with specific ESXi optimisation mode that kills running virtual machines before encrypting .vmdk, .vmx, and snapshot files
  • Partial encryption for large files (first and last 20% plus random chunks) to maximise speed while ensuring files cannot be recovered without the key
  • AES-256 in CBC mode for file content, with RSA-2048 key encapsulation
  • Embedded affiliate configuration (victim ID, ransom note content, leak site URL) generated at build time for each campaign

Extension: Encrypted files receive a .arcus extension appended to the original filename.

Ransom note: Dropped as ARCUS-README.txt in each affected directory. Notes are professionally written and include a victim-specific Tor-based negotiation portal URL, a 72-hour initial deadline, and a warning that data will be published on the leak site if contact is not established.

Evasion: The encryptor performs several evasion routines on launch: checking for common sandbox indicators (uptime below 3 minutes, minimal RAM, VM-specific registry keys), deleting Volume Shadow Copies via vssadmin.exe, disabling Windows event log collection via wevtutil, and clearing Windows Defender exclusion entries before adding itself.

Initial Access Tradecraft

Arcus Media affiliates show a preference for credential-based initial access over phishing — consistent with the group’s targeting of organisations that maintain internet-facing VPN and remote access infrastructure.

VPN appliance exploitation: Affiliates have been observed exploiting known vulnerabilities in Cisco ASA, Fortinet FortiGate, and Ivanti Connect Secure appliances. CVEs used include FortiGate credential dump vulnerabilities (CVE-2022-40684 and successors) and Ivanti authentication bypass vulnerabilities disclosed in early 2024. Unpatched appliances are identified via Shodan and commercial attack surface management tools.

Credential stuffing from infostealer logs: Arcus Media affiliates purchase credentials harvested by commodity stealers (Lumma, RedLine, Vidar) from initial access brokers, then validate them against VPN portals and M365/Entra ID tenants. Organisations that reuse credentials across services and lack phishing-resistant MFA are particularly vulnerable to this entry vector.

Managed service provider targeting: Several confirmed Arcus Media victims were breached through their MSP, enabling the affiliates to reach multiple end-client environments through a single compromised provider relationship.

Post-Compromise Behaviour

Arcus Media affiliates follow a recognisable post-compromise pattern observed across multiple incident response engagements:

Initial reconnaissance (hours 0-4): ADExplorer or Bloodhound for Active Directory enumeration, network scanning with Nmap or Advanced Port Scanner, identifying backup infrastructure and administrative shares.

Lateral movement (hours 4-48): Impacket (PsExec/WMIExec) for lateral movement, credential dumping via Mimikatz or SecretsDump, targeting domain controller access.

Data staging and exfiltration (hours 24-96): MEGAsync or rclone for bulk data exfiltration to attacker-controlled cloud storage or MEGA accounts. Arcus Media affiliates have been observed staging data for several days before deploying the encryptor — ensuring a complete exfiltration before triggering detection.

Backup destruction: Targeting backup systems is a deliberate step in Arcus Media engagements. Affiliates specifically identify Veeam, Veritas Backup Exec, and Windows Server Backup infrastructure and either delete backup catalogues or encrypt backup repositories alongside production data.

Encryptor deployment: Deployed via Group Policy Object, PsExec campaigns from a compromised domain controller, or scheduled tasks pushed across the estate. ESXi hosts receive direct encryptor deployment via SSH using harvested ESXi credentials.

Targeting and Victim Profile

Arcus Media’s victim selection appears strategic rather than opportunistic. The group demonstrates knowledge of sector-specific regulatory pressure and uses it in negotiations — referencing HIPAA breach notification costs in healthcare negotiations and GDPR fines in European victim negotiations.

Healthcare: Hospitals and health systems represent the largest single sector in Arcus Media’s disclosed victim list. The group targets patient data — PHI in HIPAA terms — as leverage in negotiations, knowing that healthcare organisations face specific notification obligations and reputational consequences from patient data exposure. Victim ransom demands in the healthcare sector average higher than other sectors.

Utilities and critical infrastructure: The group’s targeting of utilities, water authorities, and energy sector organisations is significant. These victims are under regulatory requirements that complicate ransomware response, often run OT environments that cannot easily be rebuilt, and face pressure to restore operations quickly. All of these factors increase willingness to pay.

Education and government: Regional local government and higher education institutions represent softer targets with limited security resources, high data sensitivity (student records, public service data), and — in the local government case — constrained incident response capacity.

Affiliate Programme and RaaS Structure

Arcus Media recruits affiliates through dark web forums and private channels. Published terms (analysed from forum posts and affiliate panel leaks) include:

  • Revenue split: 80/20 in the affiliate’s favour for the first three successful campaigns, moving to 85/15 for proven affiliates — unusually generous terms that reflect competitive pressure from other RaaS platforms
  • Exclusions: Healthcare may not be targeted in several Eastern European countries; Russia, CIS member states, China, and Iran are explicitly excluded targets (standard for Russian-adjacent RaaS operations)
  • Technical support: Affiliates receive encryptor builds, negotiation panel access, and access to a “locker” team for build customisation
  • No attribution: Arcus Media operates strict opsec requirements for affiliates, including mandatory use of dedicated infrastructure and prohibition on discussing operations in public forums

The exclusion list and forum language suggest Russian or Russian-adjacent operation, though attribution has not been publicly confirmed by law enforcement.

Defensive Implications

Patch VPN and remote access appliances immediately. Arcus Media’s preference for credential-based initial access via vulnerable VPN appliances makes timely patching of internet-facing infrastructure the highest-priority defensive action. CVEs exploited by affiliates are predominantly published — the risk is from organisations running months-old patch levels.

Phishing-resistant MFA. Credential stuffing from infostealer logs fails against phishing-resistant MFA (FIDO2 / hardware keys). Deploy MFA on VPN, M365, and administrative interfaces; prioritise phishing-resistant implementations over SMS or TOTP.

Backup isolation. Arcus Media affiliates specifically target backup infrastructure. Air-gap critical backups — at minimum one copy should be offline or in immutable cloud storage with no network path from production infrastructure. Test restoration regularly.

Monitor for ADExplorer and rclone. ADExplorer is not a common tool in most environments. rclone use to cloud storage endpoints from corporate endpoints warrants investigation. Both are high-fidelity indicators of post-compromise activity.

MSP security diligence. If you use an MSP, their compromise is your compromise. Review your MSP’s security posture, verify MFA requirements for their access to your environments, and ensure your monitoring covers MSP-origin activity.

Arcus Media’s low public profile has allowed it to operate with less disruption than higher-profile groups. Security teams that have focused monitoring on LockBit, RansomHub, and Cl0p should include Arcus Media in their threat intelligence feeds.

// Related Intelligence
Group Profile

Embargo Ransomware: Rust-Based RaaS Targeting Enterprise and Healthcare

Group Profile

Spirals Ransomware: New Group Completes Full Attack Chain in Under 24 Hours

Group Profile

RansomExx: Long-Running Enterprise Ransomware Group Targeting Critical Infrastructure and Government