U.S. and private-sector reporting tied North Korea-linked operators to intrusions and ransomware activity affecting healthcare, medical research, and energy-related organizations, with proceeds assessed to support DPRK cyber operations. CISA warned that ransomware attacks on critical infrastructure, particularly healthcare and public health entities, were being used to generate revenue for North Korean malicious cyber activity, while WithSecure detailed a Lazarus campaign that compromised medical research and energy supply-chain targets through unpatched Zimbra servers using CVE-2022-27925 and CVE-2022-37042, then escalated privileges with CVE-2021-4034 and moved into Windows environments for credential theft, persistence, and data theft.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
A Lazarus-linked IP address, 23.237.32[.]34, exchanged data 1,158 times with an IP attributed to a U.S. state government on a single day. SecurityScorecard identified the government IP's hostname as a subdomain associated with the state's oil and gas board web applications.
CISA and U.S. and South Korean partner agencies published a #StopRansomware alert on ransomware attacks against healthcare and public health organizations. The alert attributed the activity to DPRK state-sponsored actors and said ransomware revenue supported broader North Korean cyber priorities.
SecurityScorecard found that a Lazarus-linked IP address, 146.185.26[.]150, communicated with an IP registered to a U.S. state government. The report suggested the low-volume traffic may represent an early-stage attempt to access state resources, while noting alternative explanations remained plausible.
The observed period during which nearly 100GB of data was exfiltrated from the victim network concluded on November 11. By this stage, the attackers had established persistence, harvested credentials, and moved laterally across internal systems.
WithSecure observed nearly 100GB of data exfiltrated from the victim network over a multi-day period using encrypted SSH and SCP-based transfers. The activity supported the assessment that the campaign was focused on espionage rather than destruction.
The attackers laterally moved from the Zimbra server to a vulnerable domain-joined Windows XP device. This marked the campaign's expansion from the initial Linux mail server foothold into the Windows domain.
WithSecure observed approximately 5GB of data exfiltrated from the compromised Zimbra server, likely mailbox contents. The theft followed credential harvesting and mailbox extraction activity on the server.
On the same day, 3ByzggH211WiSPuqK6AvAGuvSE2dbduHvM and eight co-spending addresses sent the received funds to 25 other addresses. SecurityScorecard assessed the co-spending pattern may indicate common control by the same threat actors.
The wallet address bc1q8xyt4jxhw7mgqpwd6qfdjyxgvjeuz57jxrvgk9 sent 0.512 BTC to 3ByzggH211WiSPuqK6AvAGuvSE2dbduHvM. SecurityScorecard later connected the recipient and related co-spending addresses to possible laundering or support activity.
The recipient wallet bc1qhjnxutw0qvah8rea430ark2df2fcxm5xlfy52r distributed approximately the same amount it had received to three other addresses. The report said those recipient addresses had not been publicly tied to malicious activity but warranted scrutiny.
The wallet address bc1q3wzxvu8yhs8h7mlkmf7277wyklkah9k4sm9anu sent approximately 2.5 BTC to bc1qhjnxutw0qvah8rea430ark2df2fcxm5xlfy52r. SecurityScorecard later flagged the recipient chain for further investigation because it received funds from an address linked to DPRK-attributed cybercrime.
The same wallet, 1J8spy62o7z2AjQxoUpiCGnBh5cRWKVWJC, sent additional bitcoin to downstream addresses including 126JwZtwEPRuQgcPZqVPSuN1XBPUyMxjho. One recipient later forwarded roughly equivalent amounts to addresses identified as likely laundering destinations.
A bitcoin wallet address listed in later DPRK ransomware reporting, 1J8spy62o7z2AjQxoUpiCGnBh5cRWKVWJC, sent funds to multiple downstream wallet addresses. SecurityScorecard later assessed some of these transfers as likely part of laundering activity.
SecurityScorecard published analysis enriching a CISA DPRK ransomware alert with NetFlow and blockchain data. The report highlighted possible higher-education targeting and identified downstream wallet activity assessed as likely laundering of ransomware proceeds.
SecurityScorecard published research enriching ten Lazarus-linked IP indicators from an earlier healthcare research intrusion and highlighted suspicious traffic involving U.S. state government IP addresses. The firm assessed with low confidence that the traffic may reflect targeting of state government energy-related assets.
WithSecure reported that a DPRK-linked Lazarus intrusion campaign in Q4 2022 began by exploiting unpatched internet-facing Zimbra servers using CVE-2022-27925 and CVE-2022-37042 to deploy JSP webshells. The campaign targeted medical research, energy, and related supply chains for intelligence collection.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcesecurityscorecard.com
Open sourcecisa.gov
Open sourcelabs.withsecure.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.