Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

Seimas priėmė pataisas dėl pilietybės atėmimo: opozicija įžvelgė prieštaravimų Konstitucijai

March 23, 2023

TikTok chief ‘evasive’ on ‘pretty easy question’ about China’s Uyghur abuses

March 23, 2023

Navele sub pavilionul Moldovei, revizuite tehnic conform rigorilor UE

March 23, 2023
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Thursday, March 23
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • Seimas priėmė pataisas dėl pilietybės atėmimo: opozicija įžvelgė prieštaravimų Konstitucijai
  • TikTok chief ‘evasive’ on ‘pretty easy question’ about China’s Uyghur abuses
  • Navele sub pavilionul Moldovei, revizuite tehnic conform rigorilor UE
  • Prezidentas sureagavo į kritiką dėl žmonos sesers įdarbinimo: jeigu kas nors pasakytų, kad protegavau, tą pačią dieną atsistatydinsiu
  • Mureșan, alături de Mihai Popșoi: Securitatea Moldovei e în interesul UE
  • Boris Johnson should quit as MP, says Covid bereaved daughter
  • Popșoi, la Bruxelles: Dosarul Șor, o rușine pentru justiția din Moldova
  • A.Armonaitė: dalykinių argumentų, kodėl turėčiau trauktis, negirdžiu ir nematau
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » Feds warn of North Korean ransomware attacks on the health care sector

Feds warn of North Korean ransomware attacks on the health care sector

July 7, 20223 Mins Read United States
Share
Facebook Twitter LinkedIn Pinterest Email

North Korea-sponsored cyberattackers have targeted the health care sector with crushing ransomware, U.S. national security officials warned.

The cyberattackers have targeted health care organizations since at least May 2021 using Maui ransomware, according to a joint advisory from the FBI, Treasury and the Cybersecurity and Infrastructure Security Agency. 

“North Korean state-sponsored cyber actors used Maui ransomware in these incidents to encrypt servers responsible for health care services — including electronic health records services, diagnostics services, imaging services, and intranet services,” the agencies said. “In some cases, these incidents disrupted the services provided by the targeted [health care and public health] sector organizations for prolonged periods.” 

The agencies did not know the initial access points that the cyberattackers used in the attacks. 

Cybersecurity company Stairwell investigated Maui ransomware in June and said it discovered that unlike other ransomware services, Maui doesn’t include an embedded ransom note with instructions for how victims may recover systems. 

Stairwell principal reverse engineer Silas Cutler’s threat report on Maui said that the ransomware appeared to be manually operated to specify which files to encrypt in an attack, whereas other ransomware attackers may use automated means. 


SEE ALSO: North Korea ramped up hacking attempts in 2021: Report


Mandiant Intelligence Vice President John Hultquist said his team spotted North Korean cyberattackers shifting targets from health care organizations to traditional diplomatic and military organizations but the health care sector remains extremely vulnerable to extortion.

“Ransomware attacks against health care are an interesting development, in light of the focus these actors have made on this sector since the emergence of COVID-19,” Mr. Hultquist said in a statement. “It is not unusual for an actor to monetize access which may have been initially garnered as part of a cyber espionage campaign.”

The Biden administration’s new alert comes after an advisory in May saying that North Korea dispatched workers to infiltrate the tech sector to benefit the authoritarian country’s weapons and missile programs. 

That alert noted that while the IT workers normally engage in routine information technology work they also “have used the privileged access gained as contractors to enable [Democratic People’s Republic of Korea’s] malicious cyber intrusions.” 

Whether there is a connection between the warning on North Korean infiltrators and the cyberattacks on the health care sector is not fully known. Emsisoft threat analyst Brett Callow said a connection is possible.

“While I’m not aware of any evidence [directly] linking DPRK IT workers to ransomware attacks, it’s certainly something that could have happened,” Mr. Callow said in an email to The Washington Times. “Depending on their role, they could have the necessary access to deploy ransomware or to assist malicious actors to gain access to their employers’ network.”


SEE ALSO: China-sponsored hackers compromise six U.S. state gov’t networks, cybersecurity firm says


Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

TikTok chief ‘evasive’ on ‘pretty easy question’ about China’s Uyghur abuses

March 23, 2023 United States

‘Squad’ Dem says banning TikTok is ‘racist’ to Chinese, claims U.S. social media apps pose the real threat

March 23, 2023 United States

Oops, they did it again! Media falls for another Trump spectacular

March 23, 2023 United States

Maybe Putin should be worried: Most leaders facing international justice don’t get away free

March 23, 2023 United States

Rob Walker exposed as financier in mystery payouts to the Biden family

March 23, 2023 United States

GOP, Dem lawmakers call for ‘World War II-style’ military investments to deter China

March 23, 2023 United States
Don't Miss
United States

TikTok chief ‘evasive’ on ‘pretty easy question’ about China’s Uyghur abuses

By woe whMarch 23, 20230

TikTok CEO Shou Zi Chew proved evasive on direct questions about China’s human rights abuses…

Navele sub pavilionul Moldovei, revizuite tehnic conform rigorilor UE

March 23, 2023

Prezidentas sureagavo į kritiką dėl žmonos sesers įdarbinimo: jeigu kas nors pasakytų, kad protegavau, tą pačią dieną atsistatydinsiu

March 23, 2023

Mureșan, alături de Mihai Popșoi: Securitatea Moldovei e în interesul UE

March 23, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Popșoi, la Bruxelles: Dosarul Șor, o rușine pentru justiția din Moldova

March 23, 2023

A.Armonaitė: dalykinių argumentų, kodėl turėčiau trauktis, negirdžiu ir nematau

March 23, 2023

‘Squad’ Dem says banning TikTok is ‘racist’ to Chinese, claims U.S. social media apps pose the real threat

March 23, 2023

‘Cult’ of Boris Johnson ‘in death throes’ as Tory support fades

March 23, 2023

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2023 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.