Living Off the Land: The “Ghost” Cyber Attack Healthcare Teams Are Struggling to See

There is a class of attack that has no malware signature, leaves no suspicious executable on disk, and moves entirely through tools your IT team installed and trusts. Security researchers call it living off the land. In healthcare environments, it is one of the hardest threats to detect and one of the most dangerous.

BLUF — Bottom Line Up Front
  • Living-off-the-land attacks use the operating system’s own native tools, so there is no malicious artifact to match
  • PowerShell, WMI, RDP, and scheduled tasks are standard administrative utilities, which is exactly why they work as attack infrastructure
  • Hospitals generate dense legitimate administrative activity that provides ideal cover
  • Shared clinical credentials make identity-centric detection unreliable in exactly the environments that need it most
  • By the time a living-off-the-land attacker is detected, dwell time is typically measured in weeks or months
  • The tool is legitimate and the credential is valid, so behavior is the only reliable signal

What Living Off the Land Means

Living off the land (LOTL) attacks use the operating system’s own native tools to carry out every stage of an intrusion. PowerShell for scripting. Windows Management Instrumentation (WMI) for remote execution. Remote Desktop Protocol (RDP) for access. Scheduled tasks for persistence. File transfer utilities for staging data.

None of these tools are malicious. They are standard administrative utilities present in virtually every Windows environment. That is the point. An attacker using PowerShell to move laterally looks exactly like an IT administrator using PowerShell to manage systems. The activity is real. The tool is legitimate. The behavior is abnormal, but most detection platforms are not watching for behavioral abnormality. They are watching for known-bad artifacts, and there are none.

By the time a living-off-the-land attacker is detected, they have typically been inside the environment for weeks or months. The damage compounds with every day of undetected dwell time.

Why Healthcare Is Especially Exposed

Hospital networks have characteristics that make LOTL attacks particularly effective.

Dense legitimate administrative activity. Hospitals run constant IT operations: software updates, patch deployments, system configurations, remote support sessions. The volume of legitimate PowerShell, RDP, and WMI activity provides ideal cover for an attacker doing the same things with different intent.

Shared credentials. When nurses share workstation logins and clinical systems authenticate with generic service accounts, individual behavioral baselines are impossible to establish with identity-centric tools. An attacker operating under a shared credential is invisible to anything that relies on identity to detect threats.

Third-party vendor access. Healthcare networks commonly experience LOTL attacks through compromised vendor or partner accounts. Vendors with remote access already have legitimate pathways into sensitive systems. Attackers who compromise those accounts inherit those pathways and use the vendors’ own approved tools to move around.

Unagentable devices. MRI machines, infusion pumps, and legacy clinical systems cannot run endpoint detection software. Any attacker who routes their activity through or near those systems has partial cover from tools that can only see what agents report.

The Attack Pattern

A typical LOTL intrusion in a healthcare environment follows a recognizable progression, even though no individual step looks malicious in isolation.

The attacker gains initial access, usually through phishing, a compromised vendor account, or a reused credential from a previous breach. Once inside, they use WMI or PowerShell to enumerate the environment: what systems are present, who has administrative access, where sensitive data lives, what the naming conventions are.

They then use RDP or legitimate remote management tools to move laterally, reaching adjacent systems using valid credentials acquired from memory or credential stores. They establish persistence through scheduled tasks or services that blend with the existing administrative footprint. Finally, they stage data using native file utilities and exfiltrate through cloud services or protocols that the environment allows outbound.

No malware was installed. No signature was matched. No rule fired.

What Each Approach Sees

Traditional security sees
  • Authorized PowerShell session, normal
  • Valid RDP connection, normal
  • No known-bad binary, no alert fires
  • Traffic below threshold, nothing escalated
Personam detects
  • PowerShell from a host that has never run it
  • RDP to a system outside the user’s historical scope
  • Lateral movement well outside peer group baseline
  • Data staged to a cloud service never used by this entity

Why Behavioral Detection Is the Answer

The only reliable defense against living-off-the-land attacks is behavioral visibility. The attacker can keep changing the script, the entry path, the lateral movement method. They cannot change the fact that they are doing things entities in your environment do not normally do.

Personam builds a behavioral profile for every entity on your network from its first packet: users, devices, service accounts, clinical systems, everything. When any entity begins acting outside its established pattern, accessing systems it has never reached, communicating with peer groups it has never contacted, staging data volumes inconsistent with its historical behavior, Personam detects it and surfaces it for investigation.

The tool is legitimate. The credential is valid. The behavior is wrong. That is what Personam sees.

Sources
  • CISA Advisory AA23-025A: Protecting Against Malicious Use of Remote Monitoring and Management Software
  • Microsoft Security Blog: Defending against living-off-the-land techniques
  • HHS 405(d): Hospital Cyber Resiliency Initiative Landscape Analysis

See what Personam finds in your network. Live demo, 30 minutes.

Schedule Demo