IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Maui ransomware actively targeting US healthcare organizations

North Korean state-sponsored attackers are said to have been targeting critical services since at least May 2021

North Korean state-sponsored ransomware operators are running a campaign actively targeting healthcare organizations, according to an advisory issued by the FBI alongside the Cybersecurity and Infrastructure Security Agency (CISA) and the Treasury Department.

The Maui ransomware strain has been used by North Korean hackers since “at least May 2021”, according to the joint advisory

The FBI also states it’s observed and responded to “multiple ransomware incidents” at healthcare providers across the sector, in which the malicious software is being used to encrypt servers responsible for healthcare services. 

These incidents include critical elements such as electronic healthcare records services, as well as diagnostic, imagining, and intranet services. In some cases, these were found to have disrupted the services provided by the targeted organizations for prolonged periods.

The CSA said that the state-sponsored cyber criminals likely assume healthcare organizations would be willing to pay large ransoms because they provide services critical to human life and health. 

“Because of this assumption, the FBI, CISA, and Treasury assess North Korean state-sponsored actors are likely to continue targeting HPH Sector organizations,” it warned.

Minimising the ransomware risk

Although it’s not known exactly how the hackers gain initial access to these healthcare systems, the CSA notes the ransomware is designed for manual execution. Essentially, the remote actor will use a command-line interface to interact with the malware and to identify which files to encrypt. 

To help mitigate potential damage, organizations are urged to implement and maintain a number of practices. These include limiting access to data using authentications and digital certificates, minimising use of administrative accounts, turning off network device management interfaces for wide area networks (WANs), as well as using a host of other tools to secure personal identifiable information.

Additionally, the authorities said healthcare organizations should follow its list of cyber security recommendations for preparing for, mitigating, and preventing ransomware. Crucially, however, the document advises organizations against caving in to the demands of the cyber criminals.

A rise in healthcare attacks

Unfortunately, ransomware attacks on healthcare organisations and services are increasing at a rapid pace. Back in June, cloud security firm Zscaler’s 2022 ThreatLabz Ransomware Report found that attacks on the healthcare sector had grown exponentially, with double extortion ransomware attacks increasing by a staggering 650% over 2021.

Related Resource

Unified endpoint management solutions 2021-22

Analysing the UEM landscape

Whitepaper cover with title on shaded pink/purple backgroundFree Download

Elsewhere, an Outpost24 report last year found that 90% of web applications used by healthcare operators are considered ‘critically exposed’ and highly susceptible to vulnerabilities. 

That report also found US healthcare organizations have a much larger attack surface when compared to EU pharmaceutical organizations, despite US healthcare providers 30% fewer external web applications.

“Any kind of data breach and downtime for healthcare organizations can be fatal, therefore they must take a proactive stance to identify and mitigate potential security issues before critical care can be impacted,” said Nicolas Renard, security researcher at Outpost24, at the time.

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Recommended

Google adds stronger safeguards for Workspace accounts
collaboration

Google adds stronger safeguards for Workspace accounts

11 Aug 2022
DoD taps up Torch.AI to strengthen cyber security capabilities
cyber security

DoD taps up Torch.AI to strengthen cyber security capabilities

11 Aug 2022
FedEx to invest in more robotic automation from Berkshire Grey
Business strategy

FedEx to invest in more robotic automation from Berkshire Grey

4 Aug 2022
Ransomware now strikes one in 40 organisations per week, Check Point finds
ransomware

Ransomware now strikes one in 40 organisations per week, Check Point finds

27 Jul 2022

Most Popular

Cyber attack on software supplier causes "major outage" across the NHS
cyber attacks

Cyber attack on software supplier causes "major outage" across the NHS

8 Aug 2022
Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
Electrical explosion reported at Google's Iowa data centre
data centres

Electrical explosion reported at Google's Iowa data centre

9 Aug 2022