Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities

2023-02-09 USCISA

https://www.cisa.gov/uscert/ncas/alerts/aa23-040a

Thumbnail for Ransomware Attacks on Critical Infrastructure Fund DPRK Malicious Cyber Activities

This advisory highlights TTPs and IOCs DPRK cyber actors used to gain access to and conduct ransomware attacks against Healthcare and Public Health (HPH) Sector organizations and other critical infrastructure sector entities, as well as DPRK cyber actors’ use of cryptocurrency to demand ransoms. This CSA provides an overview of Democratic People’s Republic of Korea (DPRK) state-sponsored ransomware and updates the July 6, 2022, joint CSA North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector. This CSA is supplementary to previous reports on malicious cyber actor activities involving DPRK ransomware campaigns—namely Maui and H0lyGh0st ransomware. The authoring agencies are issuing this advisory to highlight additional observed TTPs DPRK cyber actors are using to conduct ransomware attacks targeting South Korean and U.S.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0837dd54268c373069fc5c1628c6e3d… 2023-02-09 2024-12-13
HASH f32f6b229913d68daad937cc72a57aa… 2021-12-22 2024-12-13
HASH ddb1f970371fa32faae61fc5b8423d4b 2023-02-09 2024-07-25
HASH a2c2099d503fcc29478205f5aef0283b 2023-02-09 2024-07-25
HASH 58ad3103295afcc22bde8d81e77c282f 2023-02-09 2024-07-25
HASH 8b395cc6ecdec0900facf6e93ec48fbb 2023-02-09 2024-07-25
HASH dda53eee2c5cb0abdbf5242f5e82f4d… 2022-09-08 2024-07-25
HASH c2904dc8bbb569536c742fca0c51a76… 2022-09-08 2024-07-25
HASH 8ce219552e235dcaf1c694be122d633… 2022-09-08 2024-07-25
HASH 90fb0cd574155fd8667d20f97ac464e… 2022-09-08 2024-07-25
HASH 4118d9adce7350c3eedeb056a3335346 2022-07-06 2024-07-25
HASH 9b0e7c460a80f740d455a7521f0eada1 2022-07-06 2024-07-25
HASH 2d02f5499d35a8dffb4c8bc0b7fec5c2 2022-07-06 2024-07-25
HASH f226086b5959eb96bd30dec0ffcbf0f… 2022-06-30 2024-07-25
HASH 17c46ed7b80c2e4dbea6d0e88ea0827c 2022-04-28 2024-07-25
HASH 079b4588eaa99a1e802adf5e0b26d8aa 2022-04-28 2024-07-25
HASH 99fc54786a72f32fd44c7391c2171ca… 2022-07-14 2024-03-17
IPv4 119.205.197.111 2023-02-09 2024-01-29
DOMAIN xpopup.com 2023-02-09 2024-01-29
IPv4 115.68.95.128 2022-09-08 2024-01-29
HASH a1f9e9f5061313325a275d448d4ddd59 2023-02-09 2023-02-10
HASH d6a7b5db62bf7815a10a17cdf7ddbd4b 2023-02-09 2023-02-10
HASH 70652edadedbacfd30d33a826853467d 2023-02-09 2023-02-10
HASH 894de380a249e677be2acb8fbdfba2ef 2023-02-09 2023-02-10
HASH 5ae71e8440bf33b46554ce7a7f3de666 2023-02-09 2023-02-10
HASH c3850f4cc12717c2b54753f8ca5d5e0e 2023-02-09 2023-02-10
HASH 43e756d80225bdf1200bc34eef5adca8 2023-02-09 2023-02-10
HASH 40f21743f9cb927b2c84ecdb7dfb14a6 2023-02-09 2023-02-10
HASH cf8ba073db7f4023af2b13dd75565f3d 2023-02-09 2023-02-10
HASH 0e9e256d8173854a7bc26982b1dde783 2023-02-09 2023-02-10
HASH 505262547f8879249794fc31eea41fc6 2023-02-09 2023-02-10
HASH 12c15a477e1a96120c09a860c9d479b3 2023-02-09 2023-02-10
HASH 92a6c017830cda80133bf97eb77d3292 2023-02-09 2023-02-10
HASH 9b9d4cb1f681f19417e541178d8c75d7 2023-02-09 2023-02-10
HASH 891db50188a90ddacfaf7567d2d0355d 2023-02-09 2023-02-10
HASH 25ee4001eb4e91f7ea0bc5d07f2a9744 2023-02-09 2023-02-10
HASH 1f239db751ce9a374eb9f908c74a31c9 2023-02-09 2023-02-10
HASH 6fb13b1b4b42bac05a2ba629f04e3d03 2023-02-09 2023-02-10
HASH 76c3d2092737d964dfd627f1ced0af80 2023-02-09 2023-02-10
HASH 640e70b0230dc026eff922fb1e44c2ea 2023-02-09 2023-02-10
HASH 1f6d9f8fbdbbd4e6ed8cd73b9e95a928 2023-02-09 2023-02-10
HASH 4e71d52fc39f89204a734b19db1330d3 2023-02-09 2023-02-10
HASH 43d4994635f72852f719abb604c4a8a1 2023-02-09 2023-02-10
HASH 67f4dad1a94ed8a47283c2c0c05a7594 2022-11-15 2023-02-10
HASH 1a74c8d8b74ca2411c1d3d22373a6769 2022-11-15 2023-02-10
HASH cf236bf5b41d26967b1ce04ebbdb4041 2022-08-09 2023-02-10
HASH 131fc4375971af391b459de33f81c253 2022-05-12 2023-02-10
HASH 830bc975a04ab0f62bfedf27f7aca673 2022-05-12 2023-02-10
HASH 85995257ac07ae5a6b4a86758a2283d7 2022-05-12 2023-02-10
HASH 87a6bda486554ab16c82bdfb12452e8b 2022-05-12 2023-02-10
HASH 827103a6b6185191fd5618b7e82da292 2022-05-12 2023-02-10
HASH b1c1d28dc7da1d58abab73fa98f60a83 2022-04-28 2023-02-10
HASH 5c6f9c83426c6d33ff2d4e72c039b747 2022-04-28 2023-02-10
HASH 1875f6a68f70bee316c8a6eda9ebf8de 2022-04-28 2023-02-10
HASH bdece9758bf34fcad9cba1394519019b 2022-04-28 2023-02-10
HASH 47791bf9e017e3001ddc68a7351ca2d6 2022-04-28 2023-02-10
HASH 2e18350194e59bc6a2a3f6d59da11bd8 2022-04-28 2023-02-10
HASH d0e203e8845bf282475a8f816340f2e8 2022-04-28 2023-02-10
HASH 85f6e3e3f0bdd0c1b3084fc86ee59d19 2022-04-28 2023-02-10
HASH 5130888a0ad3d64ad33c65de696d3fa2 2022-04-28 2023-02-10
HASH 5be1e382cd9730fbe386b69bd8045ee7 2022-04-28 2023-02-10
HASH 3bd22e0ac965ebb6a18bb71ba39e96dc 2022-04-28 2023-02-10
HASH df0c7bb88e3c67d849d78d13cee3067… 2023-02-09 2023-02-09
HASH 99b448e91669b92c2cc3417a4d97112… 2023-02-09 2023-02-09
HASH 3fe624c33790b409421f4fa2bb8abfd… 2023-02-09 2023-02-09
HASH 9d6de05f9a3e62044ad9ae66111308c… 2023-02-09 2023-02-09
HASH afb2d4d88f59e528f0e388705113ae5… 2023-02-09 2023-02-09
HASH f4d10b08d7dacd8fe33a6b54a0416ee… 2023-02-09 2023-02-09
HASH d1aba3f95f11fc6e5fec7694d188919… 2023-02-09 2023-02-09
HASH eaf6896b361121b2c315a35be837576d 2023-02-09 2023-02-09
HASH 0054147db54544d77a9efd9baf5ec96… 2023-02-09 2023-02-09
HASH 5081f54761947bc9ce4aa2a259a0bd6… 2023-02-09 2023-02-09
HASH f6375c5276d1178a2a0fe1a16c5668c… 2023-02-09 2023-02-09
HASH 2d978df8df0cf33830aba16c6322198… 2023-02-09 2023-02-09
HASH 655aa64860f1655081489cf85b77f72… 2023-02-09 2023-02-09
HASH e4ee611533a28648a350f2dab85bb72a 2023-02-09 2023-02-09
HASH 672ec8899b8ee513dbfc4590440a610… 2023-02-09 2023-02-09
HASH ba8f9e7afe5f78494c111971c39a891… 2023-02-09 2023-02-09
HASH 151ab3e05a23e9ccd03a6c49830dabb… 2023-02-09 2023-02-09
HASH 863b707873f7d653911e46885e26138… 2023-02-09 2023-02-09
HASH c6949a99c60ef29d20ac8a9a3fb58ce5 2023-02-09 2023-02-09
HASH 9c516e5b95a7e4169ecbd133ed4d205f 2023-02-09 2023-02-09
HASH f5f6e538001803b0aa008422caf2c3c… 2023-02-09 2023-02-09
HASH 18b75949e03f8dcad513426f1f9f3ca… 2023-02-09 2023-02-09
HASH 980bb08ef3e8afcb8c0c1a879ec11c4… 2023-02-09 2023-02-09
HASH c92c1f3e77a1876086ce530e87aa9c1… 2023-02-09 2023-02-09
HASH b9af4660da00c7fa975910d0a19fda0… 2023-02-09 2023-02-09
HASH 6e20b73a6057f8ff75c49e1b7aef08a… 2023-02-09 2023-02-09
HASH f67ee77d6129bd1bcd5d856c0fc5314… 2023-02-09 2023-02-09
HASH 4f089afa51fd0c1b2a39cc11cedb3a4… 2023-02-09 2023-02-09
HASH 18126be163eb7df2194bb902c359ba8e 2023-02-09 2023-02-09
HASH 6319102bac226dfc117c3c9e620cd99… 2023-02-09 2023-02-09
HASH 4b20641c759ed563757cdd95c651ee53 2023-02-09 2023-02-09
HASH 38491f48d0cbaab7305b5ddca64ba41… 2023-02-09 2023-02-09
HASH dfdd72c9ce1212f9d9455e2bca5a327… 2023-02-09 2023-02-09
HASH 5ad106e333de056eac78403b033b89c… 2023-02-09 2023-02-09
HASH a3b7e88d998078cfd8cdf37fa5454c4… 2023-02-09 2023-02-09
HASH f1576627e8130e6d5fde0dbe3dffcc8… 2023-02-09 2023-02-09
HASH e268cb7ab778564e88d757db4152b9fa 2023-02-09 2023-02-09
HASH 6b7f566889b80d1dba4f92d5e2fb2f5… 2023-02-09 2023-02-09
HASH b6f91a965b8404d1a276e43e61319931 2023-02-09 2023-02-09
HASH 6263e421e397db821669420489d2d30… 2023-02-09 2023-02-09
URL https://forum.terra-master.com/… 2023-02-09 2023-02-09
DOMAIN octagon.net 2023-02-09 2023-02-09
DOMAIN forum.terra-master.com 2023-02-09 2023-02-09
DOMAIN xpopup.pe.kr 2023-02-09 2023-02-09
HASH bffe910904efd1f69544daa9b72f2a7… 2022-09-07 2023-02-09
HASH f78cabf7a0e7ed3ef2d1c976c148628… 2022-09-07 2023-02-09
HASH 1c926fb3bd99f4a586ed476e4683163… 2022-09-07 2023-02-09
HASH 23eff00dde0ee27dabad28c1f4ffb8b… 2022-09-07 2023-02-09
HASH ca932ccaa30955f2fffb1122234fb15… 2022-09-07 2023-02-09
HASH 196fb1b6eff4e7a049cea323459cfd6… 2022-09-07 2023-02-09
HASH f6827dc5af661fbb4bf64bc625c7828… 2022-09-07 2023-02-09
HASH 739812e2ae1327a94e441719b885bd19 2022-08-09 2023-02-09
HASH 92adc5ea29491d9245876ba0b295739… 2022-08-09 2023-02-09
HASH ad4eababfe125110299e5a24be84472e 2022-08-09 2023-02-09
HASH f2f787868a3064407d79173ac5fc0864 2022-08-09 2023-02-09
HASH 6122c94cbfa11311bea7129ecd5aea6… 2022-08-09 2023-02-09
HASH 60425a4d5ee04c8ae09bfe28ca33bf9… 2022-08-09 2023-02-09
HASH a557a0c67b5baa7cf64bd4d42103d3b… 2022-08-09 2023-02-09
HASH 541825cb652606c2ea12fd25a842a8b… 2022-07-14 2023-02-09
HASH bea866b327a2dc2aa104b7ad7307008… 2022-07-14 2023-02-09
HASH f8fc2445a9814ca8cf48a979bff7f18… 2022-07-14 2023-02-09
HASH 45d8ac1ac692d6bb0fe776620371fca… 2022-07-06 2023-02-09
HASH 99b0056b7cc2e305d4ccb0ac0a8a270… 2022-07-06 2023-02-09
HASH 830207029d83fd46a4a89cd623103ba… 2022-07-06 2023-02-09
HASH 56925a1f7d853d814f80e98a1c4890b… 2022-07-06 2023-02-09
HASH a6e1efd70a077be032f052bb75544358 2022-07-06 2023-02-09
HASH 458d258005f39d72ce47c111a7d17e8… 2022-07-06 2023-02-09
HASH 3b9fe1713f638f85f20ea56fd09d20a… 2022-07-06 2023-02-09
HASH 802e7d6e80d7a60e17f9ffbd62fcbbeb 2022-07-06 2023-02-09
HASH a452a5f693036320b580d28ee55ae2a3 2022-07-06 2023-02-09
HASH c50b839f2fc3ce5a385b9ae1c05def3a 2022-07-06 2023-02-09
HASH fda3a19afa85912f6dc8452675245d6b 2022-07-06 2023-02-09
HASH 87bdb1de1dd6b0b75879d8b8aef80b5… 2022-07-06 2023-02-09
HASH 5b7ecf7e9d0715f1122baf4ce745c5f… 2022-07-06 2023-02-09
HASH 586f30907c3849c363145bfdcdabe3e… 2022-04-27 2023-02-09
HASH 414ed95d14964477bebf86dced03067… 2022-04-27 2023-02-09
HASH 1f8dcfaebbcd7e71c2872e0ba2fc6db… 2021-12-22 2023-02-09

Related Reports

2020-08-26 • 28% Match
#BeagleBoyz #FASTCash2 #T1082 #T1119 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1020 #T1560 #T1115 #T1083 #T1036 #T1027 #T1071 #T1548.003 #T1204 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1053 #T1132.001 #T1102 #T1059 #T1199 #T1105 #T1219 #T1055 #T1553.002 #T1552.004 #T1562.001 #T1486 #T1129 #T1489 #T1078 #T1133 #T1053.003 #T1190 #T1203 #T1189 #T1049 #T1098 #T1087 #T1016 #T1070.006 #T1021.001 #T1574.001 #T1217 #T1106 #T1573 #T1095 #T1056 #T1010 #T1021.002 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1110 #T1561.002 #T1202 #T1070.003 #T1565.001 #T1021 #T1505.003 #T1027.005 #T1056.004 #T1218.001 #T1562.003 #T1014 #T1053.004 #T1101 #T1565.002 #T1565.003 #T1562.006
Shares tags: T1083, T1486, T1133 • Same author: USCISA
2023-02-02 • 27% Match
#Whitepaper #NoPineapple #DTrack #GREASE #Zimbra #T1082 #T1119 #T1070.004 #T1041 #T1560 #T1071.001 #T1083 #T1071 #T1057 #T1053.005 #T1036.005 #T1059 #T1078 #T1190 #T1049 #T1016 #T1018 #T1003.001 #T1021.001 #T1106 #T1090.001 #T1074 #T1553 #T1033 #T1569.002 #T1090.002 #T1012 #T1087.002 #T1114.002 #T1505.003 #T1556 #T1037.005 #T1136 #T1070.007 #T1587.002
Shares tags: T1083, T1190 • Published within a week
« Back