U.S. authorities said North Korean state-backed cyber actors used Maui ransomware to target organizations in the Healthcare and Public Health Sector, including hospitals and health centers. A joint advisory from CISA, the FBI, and the Treasury Department linked the activity to North Korean operators and said the attacks disrupted medical services by encrypting servers and critical systems. Reporting on the campaign said victims included healthcare entities in states such as Kansas and Colorado, underscoring a focused effort against providers whose operations are highly sensitive to downtime.
The Justice Department later announced it had seized about $500,000 in cryptocurrency tied to Maui ransomware payments made after 2021 intrusions at healthcare organizations. Officials said the recovery was part of a broader effort to trace and claw back ransom proceeds connected to North Korean cyber operations, while federal agencies urged healthcare defenders to harden remote access, patch exposed systems, segment networks, and maintain offline backups to reduce the impact of ransomware attacks.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice announced the seizure of roughly $500,000 in cryptocurrency traced to ransom payments made by healthcare providers affected by Maui ransomware in 2021. The action was part of efforts to recover funds linked to North Korean cyber activity.
CISA released alert AA22-187A detailing Maui ransomware activity, associated tactics, techniques, and procedures, and mitigation guidance for defenders. The alert formalized public technical reporting on the campaign.
U.S. authorities disclosed that North Korean state-sponsored cyber actors were using Maui ransomware to target the healthcare and public health sector. The advisory described Maui as being used since at least May 2021 against healthcare entities.
In 2021, Maui ransomware was used in attacks against healthcare organizations including facilities in Kansas and Colorado. The incidents disrupted healthcare services and led the victims to make ransom payments.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
techtarget.com
Open sourcetherecord.media
Open sourcecisa.gov
Open sourcetechtarget.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.