Skip to main content
Mallory
MalwareRansomwareUsed by 6 actorsExploits 3 CVEs

Maui

Maui is a ransomware family associated with North Korean state-sponsored cyber actors, particularly the Lazarus Group and its Andariel/Stonefly sub-cluster. The provided reporting states Lazarus historically developed its own ransomware families including WannaCry, Maui, and H0lyGh0st, and that Maui has been used since at least May 2021. Multiple sources in the content link Maui to DPRK operations targeting the healthcare and public health sector, including U.S. healthcare organizations, and note that North Korean-backed Maui actors were the subject of a July 2022 advisory and a broader February 10, 2023 joint advisory by NSA, HHS, FBI, CISA, and South Korean partners. The content also states Andariel was reported deploying Maui in at least one 2022 incident and that Lazarus/Andariel used Maui alongside other bespoke ransomware families such as SHATTEREDGLASS and H0lyGh0st. High-confidence behavioral detail in the provided content is limited, but the reporting consistently characterizes Maui as custom-developed ransomware used in financially motivated DPRK intrusions, with ransom demands in bitcoin and revenue assessed to support DPRK national priorities, including follow-on cyber operations. The strongest targeting pattern directly mentioned is healthcare and public health organizations, though the content also references activity against entities in South Korea, Japan, and the United States. No specific file hashes or technical IOCs for Maui itself are provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2021-44228Log4ShellExploited in the wild

Recently observed CVEs that actors used to gain access include remote code execution in the Apache Log4j software library (known as Log4Shell)... Observed CVEs used include: CVE-2021-44228

via cisa advisoriescisa.gov
CVE-2022-24990TerraMaster TOS administrative password disclosure via User-Agent headerExploited in the wild

Observed CVEs used include: ... CVE-2022-24990 ... The TerraMaster OS Unauthenticated Remote Command Execution via PHP Object Instantiation Vulnerability is characterized by scanning activity targeting a flaw...

via cisa advisoriescisa.gov
CVE-2021-20038Unauthenticated RCE in SonicWall SMA100 Apache httpd mod_cgiExploited in the wild

Recently observed CVEs that actors used to gain access include ... remote code execution in unpatched SonicWall SMA 100 appliances... Observed CVEs used include: CVE-2021-20038

via cisa advisoriescisa.gov
THREAT ACTORS

Groups observed using it

6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Lazarus

Lazarus Group has historically built its own ransomware -- WannaCry (2017), Maui (2022), H0lyGh0st (2022).

via breakglass intelintel.breakglass.tech
Andariel

Andariel was reported deploying their signature Maui ransomware on at least one occasion in 2022

via sekoia blogblog.sekoia.io
Stonefly/Clasiopa

For more information on this ransomware activity, see... North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector.

via ic3 alertsic3.gov
North Korean state-sponsored cyber actors

"Maui ransomware, which has been used by North Korean state-sponsored cyber actors since at least May 2021 to target Healthcare and Public Health (HPH) Sector organizations."

via cisa alertscisa.gov
Contagious Interview

North Korea has long been involved in ransomware attacks and has been previously associated with the Maui and Play ransomware families.

via ctoatncsc substackctoatncsc.substack.com
DPRK cyber actors

This CSA provides an overview of Democratic People’s Republic of Korea (DPRK) state-sponsored ransomware and updates the July 6, 2022, joint CSA North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector.

via cisa advisoriescisa.gov
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583Acquire InfrastructureEvidence1

"Acquire Infrastructure [ T1583 ] . DPRK actors generate domains, personas, and accounts; and identify cryptocurrency services to conduct their ransomware operations."

T1583.003Virtual Private ServerEvidence1

"Purchase VPNs and VPSs [ T1583.003 ] . DPRK cyber actors will also use virtual private networks (VPNs) and virtual private servers (VPSs) or third-country IP addresses..."

Initial Access

3 techniques
T1133External Remote ServicesEvidence1

"...remote code execution in unpatched SonicWall SMA 100 appliances [T1190 and T1133]."

T1190Exploit Public-Facing ApplicationEvidence3

"The other victim operated a vulnerable Weblogic server... compromised this server via the CVE-2017-10271 exploit." | "In one victim system, we discovered that a well-known simple HTTP server, HFS7, had deployed the malware above. After an unknown exploit was used on a vulnerable HFS server and “whoami” was executed..."

T1195Supply Chain CompromiseEvidence1

"Actors also likely spread malicious code through Trojanized files for “X-Popup,” an open source messenger... [T1195]."

Persistence

1 technique
T1133External Remote ServicesEvidence1

"...remote code execution in unpatched SonicWall SMA 100 appliances [T1190 and T1133]."

Stealth

1 technique
T1070.004File DeletionEvidence1
TacticStealth

"“-x” commands the malware to “self melt”"

Discovery

1 technique
T1083File and Directory DiscoveryEvidence1
TacticDiscovery

"...perform reconnaissance activities, upload and download additional files and executables, and execute shell commands [T1083, T1021]."

Lateral Movement

1 technique
T1021Remote ServicesEvidence1

"...perform reconnaissance activities... and execute shell commands [T1083, T1021]."

Impact

1 technique
T1486Data Encrypted for ImpactEvidence11
TacticImpact

Additionally, Andariel was reported deploying their signature Maui ransomware on at least one occasion in 2022.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution6

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.