US and South Korea accuse North Korea of using hospital ransoms to fund more hacking

Share:

North Korean state hackers are using a variety of ransomware strains to attack healthcare organizations and other targets globally, with the goal of pulling in money to fund other operations, the U.S. and South Korea said Thursday.

The two allies said “an unspecified amount of revenue from these cryptocurrency operations supports [North Korean] national-level priorities and objectives, including cyber operations targeting the United States and South Korea governments.”

Specific targets for those cyber operations include U.S. defense information networks and military contractors, according to joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the NSA and several South Korean defense and intelligence agencies.

North Korean hackers have used both internally developed ransomware like Maui and H0lyGh0st, the agencies said, as well as other extortion malware attained by other means — such as Deadbolt, ech0raix, GonnaCry, Hidden Tear, Jigsaw, LockBit 2.0, My Little Ransomware, NxRansomware, Ryuk, and YourRansom.

The advisory provides an update on one released by the same law enforcement agencies in July 2022 – in which North Korean hackers were accused of using the Maui ransomware in attacks on healthcare organizations.

It marks the first time agencies have tied a specific actor to the use of Deadbolt and ech0raix, two ransomware strains used to target customers of data-storage hardware vendor QNAP.

The agencies also said North Korean hackers have attempted to portray themselves as members of other ransomware groups like the now-shuttered REvil.

They have generated multiple web domains, personas and accounts to obscure their actions, according to the agencies, which noted that the hackers are able to “procure infrastructure, IP addresses, and domains with cryptocurrency generated through illicit cybercrime, such as ransomware and cryptocurrency theft.”

They also use VPNs to make it appear attacks are coming from more innocuous locations outside of North Korea.

The hackers use a range of exploits for common vulnerabilities like Log4Shell and others. The agencies named three specific vulnerabilities – CVE-2021-44228CVE-2021-20038 and CVE-2022-24990 – as ones typically used by North Korean actors.

In addition to ransomware, the hackers use other customized malware to exfiltrate data, perform reconnaissance operations and steal files.

“DPRK cyber actors have been observed setting ransoms in bitcoin. Actors are known to communicate with victims via Proton Mail email accounts,” the advisory said. “For private companies in the healthcare sector, actors may threaten to expose a company’s proprietary data to competitors if ransoms are not paid.”

The advisory highlights a startling trend across the world as nation-states have begun deploying ransomware for a variety of reasons and purposes.

The governments of countries like Costa RicaAlbaniaBosnia and Herzegovina and Montenegro have each dealt with ransomware attacks that were allegedly launched by rivals or adversaries like Russia and Iran.

Several other parliaments around the world have faced off against ransomware gangs and hackers in recent years.

Allan Liska, a ransomware expert at cybersecurity company Recorded Future, said more than 50 national governments or national government agencies have been hit by ransomware in 2022. The Record is an editorially independent unit of Recorded Future.

“We’ve seen what appear to be government-backed ransomware attacks from Russia, China, Iran and North Korea. Now, North Korea has always used ransomware attacks, dating back to 2017, but they seem to have really stepped up their attacks this year, making them even more dangerous as an adversary,” he said.

 

(c) Jonathan Greig

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:18 am, Jul 14, 2025
weather icon 20°C
L: 19° | H: 22°
overcast clouds
Humidity: 74 %
Pressure: 1011 mb
Wind: 8 mph ESE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 88%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:59 am
Sunset: 9:12 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
19° | 22°°C 0 mm 0% 15 mph 75 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 21°°C 1 mm 100% 19 mph 84 % 1016 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
15° | 27°°C 0.2 mm 20% 13 mph 85 % 1017 mb 0 mm/h
Thu Jul 17 10:00 pm
weather icon
18° | 27°°C 0.76 mm 76% 10 mph 91 % 1017 mb 0 mm/h
Fri Jul 18 10:00 pm
weather icon
18° | 31°°C 0.53 mm 53% 5 mph 93 % 1015 mb 0 mm/h
Today 4:00 am
weather icon
16° | 19°°C 0 mm 0% 8 mph 72 % 1011 mb 0 mm/h
Today 7:00 am
weather icon
17° | 18°°C 0 mm 0% 10 mph 75 % 1011 mb 0 mm/h
Today 10:00 am
weather icon
21° | 21°°C 0 mm 0% 12 mph 54 % 1012 mb 0 mm/h
Today 1:00 pm
weather icon
25° | 25°°C 0 mm 0% 14 mph 36 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
25° | 25°°C 0 mm 0% 15 mph 42 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
23° | 23°°C 0 mm 0% 14 mph 33 % 1013 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 19°°C 0 mm 0% 9 mph 46 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 9 mph 61 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€101,833.09
1.50%
Ethereum(ETH)
€2,542.89
1.12%
XRP(XRP)
€2.42
3.61%
Tether(USDT)
€0.85
0.01%
Solana(SOL)
€137.68
0.23%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.169726
0.68%
Shiba Inu(SHIB)
€0.000011
1.28%
Pepe(PEPE)
€0.000010
0.52%
Peanut the Squirrel(PNUT)
€0.244320
5.81%
Scroll to Top