Maui Ransomware

#Maui • 2022-07

🇺🇸 United States, 🇯🇵 Japan

North Korean state-sponsored actors, with later reporting linking a 2021 case to Andariel, used Maui ransomware in a manually operated encryption campaign affecting healthcare and other financially viable organizations in the United States and Japan. The malware encrypted selected servers and files through command-line execution, used AES/RSA/XOR routines with local key and log artifacts, and caused disruption to healthcare services including electronic health records, diagnostics, imaging, and intranet systems.

Related Actors

Related Reports

« Back