North Korean hackers have targeted government businesses and healthcare organizations with ransomware attacks.

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about the risks of North Korean ransomware activities targeting public health and other critical infrastructure sectors, detailing the recent tactics, techniques and procedures they are using to gain access.
See also: Indigo: Site down due to cyberattack
This joint report by the NSA, FBI, CISA, US HHS, and the Republic of Korea National Intelligence Service and Defense Security Service reveals that the money raised from extortion was used to support the primary goals and intentions of the North Korean government.
CISA also revealed that malicious actors used twelve varieties of ransomware against healthcare systems in South Korea and the US.
To conceal the source of their operations, CISA found that North Korean threat actors use fake identities and accounts to obtain funding for an attack , then use cryptocurrency . In addition, they often seek out intermediaries abroad who can help further conceal the money trail.
Hackers hide their origins by using VPN services and virtual private servers (VPS) or IP addresses originating from foreign countries.
To gain access to a target network, one must exploit its vulnerabilities and escalate privileges within the system.
Among the security issues exploited are Log4Shell (CVE-2021-44228), remote code execution flaws in SonicWall devices (CVE-2021-20038), and administrator password disclosure flaws in TerraMaster NAS products (CVE-2022-24990).
After compromising a system, North Korean hackers use shell commands and deploy payloads for network reconnaissance and lateral movement to obtain further information.
See also: TA886 group attacks high-value targets with Screenshotter malware

Ransomware threats
According to the US agency, North Korean hackers are linked to the Maui and H0lyGh0st ransomware strains. However, they have also leveraged already accessible tools to encrypt data:
- BitLocker (abused of a legitimate tool)
- Deadbolt
- echoraix
- GonnaCry
- Hidden Tear
- Jigsaw
- LockBit 2.0
- My Little Ransomware
- NxRansomware
- Ryuk
- YourRansom
During the final stage of the attack, the attackers will demand a ransom in Bitcoin cryptocurrency. The attackers contact their victims via Proton Mail and typically issue warnings that the stolen data if payment is not made, especially when targeting private healthcare companies.
See also: A phishing attack can cost a business $1 million
To maximize security, healthcare organizations should adopt numerous safeguards, such as multi-factor authentication (MFA) for account security, disabling any unused interfaces, using network traffic, adhering to the principles of least privilege, and applying all available software updates. CISA strongly encourages these corrective actions to secure accounts and ensure the security of sensitive data.
Information source: bleepingcomputer.com
