Maui is a ransomware family associated with North Korean state-sponsored cyber actors, including reporting that links its use to Lazarus Group and the Andariel/Stonefly/APT45 sub-cluster. U.S. agencies reported in 2022 that DPRK actors used Maui ransomware to target healthcare and public health sector organizations, and multiple references state it has been used since at least May 2021. The malware is repeatedly described as part of North Korea’s financially motivated ransomware activity, with cryptocurrency revenue assessed by government agencies as supporting broader DPRK national priorities and follow-on cyber operations. Reported victimology centers on healthcare organizations, particularly in the healthcare and public health sector, with additional references placing related DPRK activity against entities in South Korea, Japan, and the United States. The content also notes Maui alongside other DPRK-linked ransomware families such as WannaCry, H0lyGh0st, Play, and SHATTEREDGLASS. High-confidence contextual indicators from the content are attribution and targeting related rather than technical malware IOCs: Maui ransomware activity was the subject of a July 2022 CISA advisory on North Korean state-sponsored actors targeting healthcare, and a February 2023 joint advisory further expanded on DPRK ransomware tactics involving Maui and H0lyGh0st.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently observed CVEs that actors used to gain access include remote code execution in the Apache Log4j software library (known as Log4Shell)... Observed CVEs used include: CVE-2021-44228
Observed CVEs used include: ... CVE-2022-24990 ... The TerraMaster OS Unauthenticated Remote Command Execution via PHP Object Instantiation Vulnerability is characterized by scanning activity targeting a flaw...
Recently observed CVEs that actors used to gain access include ... remote code execution in unpatched SonicWall SMA 100 appliances... Observed CVEs used include: CVE-2021-20038
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus Group has historically built its own ransomware -- WannaCry (2017), Maui (2022), H0lyGh0st (2022).
Andariel was reported deploying their signature Maui ransomware on at least one occasion in 2022
For more information on this ransomware activity, see... North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector.
North Korea has long been involved in ransomware attacks and has been previously associated with the Maui and Play ransomware families.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"...remote code execution in unpatched SonicWall SMA 100 appliances [T1190 and T1133]."
"The other victim operated a vulnerable Weblogic server... compromised this server via the CVE-2017-10271 exploit." | "In one victim system, we discovered that a well-known simple HTTP server, HFS7, had deployed the malware above. After an unknown exploit was used on a vulnerable HFS server and “whoami” was executed..."
U.S. agencies have attributed Maui ransomware activity against healthcare organizations to North Korean state-sponsored actors. | DPRK-linked actors have targeted healthcare and other critical sectors, often using ransomware. U.S. agencies have attributed Maui ransomware activity against healthcare organizations to North Korean state-sponsored actors.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used against healthcare organizations, attributed in the content to North Korean state-sponsored actors.
Referenced as a prior Lazarus-operated ransomware family historically built and controlled by the group.
Maui is cited as a ransomware family historically deployed by Lazarus Group.
Ransomware family previously associated (in the cited reporting) with North Korean state-backed activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.