US offers $10M for tips on DPRK hacker linked to Maui ransomware attacks

Teilen:

The U.S. State Department is offering a reward of up to $10 million for information that could help capture a North Korean military hacker identified as Rim Jong Hyok.

Part of the Andariel North Korean hacking group, Hyok and other Andariel operatives were linked to Maui ransomware attacks targeting critical infrastructure and healthcare organizations across the United States.

Hyok was charged with conspiracy to commit computer hacking and conspiracy to commit promotion money laundering, and a federal arrest warrant was issued in the U.S. District Court, District of Kansas, on Wednesday.

So far, U.S. law enforcement investigating their attacks has linked the North Korean hackers to ransomware incidents that impacted two U.S. Air Force bases, five healthcare providers, four U.S.-based defense contractors, and the National Aeronautics and Space Administration’s Office of Inspector General.

“Rim and others conspired to hack into the computer systems of U.S. hospitals and other healthcare providers, install Maui ransomware, and extort ransoms,” the State Department said.

“The ransomware attacks encrypted victims’ computers and servers used for medical testing or electronic medical records and disrupted healthcare services. These malicious cyber actors then used the ransom payments to fund malicious cyber operations targeting U.S. government entities and U.S. and foreign defense contractors, among others.”

In one such incident from November 2022, Andariel hackers breached the network of a U.S. defense contractor and stole more than 30 gigabytes of data, including unclassified information on military aircraft and satellites, much of it from 2010 or earlier.

​These rewards are provided through the Rewards of Justice (RFJ) program, a U.S. Department of State program that offers rewards for information on threat actors targeting U.S. national security.

The State Department has also set up a dedicated Tor SecureDrop server to submit tips on Andariel hackers or other wanted threat groups and malicious actors.

Today, CISA and the FBI (in partnership with cybersecurity agencies from the United Kingdom and the Republic of Korea) also issued a joint advisory about this hacking group, which is tracked as APT45, Onyx Sleet, DarkSeoul, Silent Chollima, and Stonefly/Clasiopa and linked to North Korea’s Reconnaissance General Bureau (RGB) 3rd Bureau.

According to this advisory, Andariel is focused on stealing “sensitive military information and intellectual property of defense, aerospace, nuclear, and engineering organizations.”

“The information targeted—such as contract specifications, bills of materials, project details, design drawings, and engineering documents—has military and civilian applications and leads the authoring agencies to assess one of the group’s chief responsibilities as satisfying collection requirements for Pyongyang’s nuclear and defense programs,” the authoring agencies added.

This hacking group is believed to be an ongoing threat to a wide range of industry sectors worldwide, and all critical infrastructure organizations are advised to implement the mitigations recommended in today’s advisory.

On Thursday, Mandiant tagged Andariel/APT45 as one of North Korea’s longest-running cyber operations, dating back to 2009. In 2019, it targeted multiple nuclear power plants and research facilities, including India’s Kudankulam Nuclear Power Plant.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:36 am, Jan. 21, 2025
Wetter-Symbol 2°C
L: 1° | H: 3°
fog
Luftfeuchtigkeit: 95 %
Druck: 1015 mb
Wind: 2 mph WNW
Windböe: 3 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 0 km
Sonnenaufgang: 7:53 am
Sonnenuntergang: 4:29 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
1° | 3°°C 0 mm 0% 4 mph 95 % 1015 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 5°°C 1 mm 100% 5 mph 97 % 1009 mb 0 mm/h
Do. Jan. 23 9:00 pm
Wetter-Symbol
2° | 9°°C 1 mm 100% 17 mph 93 % 1008 mb 0 mm/h
Fr. Jan. 24 9:00 pm
Wetter-Symbol
6° | 11°°C 1 mm 100% 24 mph 90 % 1006 mb 0 mm/h
Sa. Jan. 25 9:00 pm
Wetter-Symbol
2° | 6°°C 1 mm 100% 12 mph 99 % 1013 mb 4.43 mm/h
Today 9:00 am
Wetter-Symbol
2° | 3°°C 0 mm 0% 2 mph 95 % 1015 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
3° | 5°°C 0 mm 0% 4 mph 89 % 1015 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
4° | 6°°C 0 mm 0% 3 mph 81 % 1013 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 82 % 1012 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 91 % 1011 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 95 % 1009 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 96 % 1007 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
4° | 4°°C 0.84 mm 84% 3 mph 96 % 1005 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€98,198.00
-5.53%
Ethereum(ETH)
€3,125.58
-3.41%
XRP(XRP)
€2.96
-3.85%
Fesseln(USDT)
€0.96
0.01%
Solana(SOL)
€227.47
-8.16%
Dogecoin(DOGE)
€0.329563
-8.54%
USDC(USDC)
€0.96
0.00%
Shiba Inu(SHIB)
€0.000019
-7.04%
Pepe(PEPE)
€0.000014
-11.53%
Peanut das Eichhörnchen(PNUT)
€0.354320
-12.00%
Nach oben scrollen