A strain of ransomware targeting the US healthcare industry is linked to North Korean state-sponsored hackers, according to the FBI. The US today warned of the active use of “Maui” ransomware, which the FBI has been investigating for a year. In some cases, The attacks caused massive disruptions and delays among healthcare providers.
The Cybersecurity and Infrastructure Security Agency (CISA) suggests that health and public health (HPH) organizations in the US are the new target of these North Korean hackers, who have recently lost millions of dollars due to Bitcoin’s decline.
Maui ransomware from North Korean hackers crippling healthcare
According to US authorities, Maui ransomware was discovered by hackers. encrypt servers responsible for healthcare, including electronic medical record services, diagnostic services, imaging services, and intranet services. CISA said the ransomware appears to have been designed for remote manual execution. It also uses a combination of Advanced Encryption Standard (AES), RSA, and XOR encryption to encrypt target files.
At this time, it is unclear how the North Koreans spread the Maui ransomware to healthcare organizations. However, officials shared some tips for services affected by these ransomware attacks.
In a statement released July 6, the FBI, CISA and Treasury We strongly recommend that you do not pay the requested ransoms.because this is often does not guarantee the recovery of files and folders and may pose a risk of sanctions. These attacks by North Korean hackers have been increasing in recent months, as Google claims to have blocked North Korea from hacking Chrome. These hackers are also known to attack Windows and Android devices with Chinotto malware late last year.
Source : cisa
Support our work ❤️
If you enjoyed this article, consider leaving a tip to help us keep publishing great content.



























