News: 1657147864

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Here today, gone to Maui: That's your data captured by North Korean ransomware

(2022/07/07)


For the past year, state-sponsored hackers operating on behalf of North Korea have been using ransomware called Maui to attack healthcare organizations, US cybersecurity authorities said on Wednesday.

Uncle Sam's Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Treasury Department [1]issued a joint advisory outlining a Pyongyang-orchestrated ransomware campaign that has been underway at least since May, 2021.

The initial access vector – the way these threat actors break into organizations – is not known. Even so, the FBI says it has worked with multiple organizations in the healthcare and public health (HPH) sector infected by Maui ransomware.

[2]

"North Korean state-sponsored cyber actors used Maui ransomware in these incidents to encrypt servers responsible for healthcare services – including electronic health records services, diagnostics services, imaging services, and intranet services," the [3]joint security advisory [PDF] reads. "In some cases, these incidents disrupted the services provided by the targeted HPH Sector organizations for prolonged periods."

[4]

[5]

The Feds assume the reason HPH sector organizations have been targeted is that they will pay ransoms rather than risk being locked out of systems, being denied data, or having critical services interrupted.

Maui, according to Silas Cutler, principal reverse engineer at security outfit Stairwell, is one of the lesser known families of ransomware. He [6]says it stands out for its lack of service-oriented tooling, such as an embedded ransom note with recovery instructions. That leads him to believe Maui is operated manually by individuals who specify which files should be encrypted and exfiltrated.

[7]FBI warns of North Korean cyberspies posing as foreign IT workers

[8]North Korea says it's launched a third hypersonic missile, this time reaching Mach 10

[9]North Korea pulled in $400m in cryptocurrency heists last year – report

[10]Cryptocurrency laundromat Blender shredded by US Treasury in sanctions first

The advisory, based on Stairwell's [11]research [PDF], indicates that the Maui ransomware is an encryption binary that a remote operator manually executes through command line interaction. The ransomware deploys AES, RSA, and XOR encryption to lock up target files. Thereafter, the victim can expect a ransom payment demand.

According to SonicWall, there were [12]304.7 million ransomware attacks in 2021, an increase of 151 percent. In healthcare, the percentage increase was 594 percent.

[13]

CrowdStrike, another security firm, in its [14]2022 Global Threat Report said North Korea has shifted its focus to cryptocurrency entities "in an effort to maintain illicit revenue generation during economic disruptions caused by the pandemic." For example, consider [15]the recent theft of $100 million of cryptocurrency assets from Harmony by the North Korea-based cybercrime group Lazarus. But organizations that typically transact with fiat currencies aren't off the hook.

Sophos, yet another security firm, said in its [16]State of Ransomware Report 2022 that the average ransom payment last year was $812,360, a 4.8X increase from the 2020 when the average payment was $170,000. The company also said more victims are paying ransoms: 11 percent in 2021 compared to 4 percent in 2020.

The advisory discourages the payment of ransoms. Nonetheless, the FBI is asking any affected organization to share information related to ransomware attacks, such as communication with foreign IP addresses, Bitcoin wallet details, and file samples. The advisory goes on to suggest ways to mitigate ransomware attacks and minimize damage.

[17]

Last month, the US Justice Department outlined its Strategic Plan for the next four years and cited [18]enhancing cybersecurity and fighting cybercrime among its objectives. One of its key metrics for success will be the "percent of reported ransomware incidents from which cases are opened, added to existing cases, or resolved or investigative actions are conducted within 72 hours." ®

Get our [19]Tech Resources



[1] https://www.cisa.gov/news/2022/07/06/cisa-fbi-and-treasury-release-advisory-north-korean-state-sponsored-cyber-actors

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsZaaCGWBNl9q0x63jaeswAAANE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.cisa.gov/uscert/sites/default/files/publications/aa22-187a-north-korean%20state-sponsored-cyber-actors-use-maui-ransomware-to-target-the-hph-sector.pdf

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsZaaCGWBNl9q0x63jaeswAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsZaaCGWBNl9q0x63jaeswAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://stairwell.com/news/threat-research-report-maui-ransomware/

[7] https://www.theregister.com/2022/05/17/fbi_korea_freelancers/

[8] https://www.theregister.com/2022/01/12/north_korea_hypersonic_missile/

[9] https://www.theregister.com/2022/01/16/in_brief_security/

[10] https://www.theregister.com/2022/05/06/us_treasury_sanctions_blender/

[11] https://stairwell.com/wp-content/uploads/2022/07/Stairwell-Threat-Report-Maui-Ransomware.pdf

[12] https://www.sonicwall.com/news/sonicwall-record-304-7-million-ransomware-attacks-eclipse-2020-global-total-in-just-6-months/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsZaaCGWBNl9q0x63jaeswAAANE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://go.crowdstrike.com/global-threat-report-2022.html

[15] https://www.theregister.com/2022/07/01/lazarus-crypto-hack-harmony/

[16] https://www.sophos.com/en-us/whitepaper/state-of-ransomware

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsZaaCGWBNl9q0x63jaeswAAANE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://www.justice.gov/doj/doj-strategic-plan/objective-24-enhance-cybersecurity-and-fight-cybercrime

[19] https://whitepapers.theregister.com/



I wonder why

M.V. Lipvig

the ransomware gangs haven't gone for the big enchilada and hit one of the major cloud providers yet. Considering who the big players are, it would probably be like sandblasting a soup cracker. Unless, perhaps they're waiting for some major players to follow Fedex into going all cloud. Imagine the uproar if some major trading houses went cloudy and the provider was locked up.

Re: I wonder why

Clausewitz4.0

QUOTE: hit one of the major cloud providers

If you get to the core of a major cloud provider, source code for the tools or the orchestrating tools itself are a much more valuable target.

It enables a shy business to deploy REDIS / NOSQL / MongoDB / etc clusters in an amazon-like-way, with a nice control panel - a shy business can potentially become a major player itself.

Name

Gene Cash

They should have called it "Lanai" after the island owned by the other ransomware operator.

It's not the valleys in life I dread so much as the dips.
-- Garfield