
The U.S. DoJ has seized $500,000 worth of Bitcoin from North Korean threat actors who used the Maui ransomware to target several organizations worldwide.
A complaint filed in the District of Kansas to forfeit cryptocurrency paid as ransom to North Korean hackers or otherwise used to launder such ransom payments. The seized funds include ransoms paid by health care providers in Kansas and Colorado.
Maui ransomware infected the servers of the hospital in the District of Kansas. They opted to pay approximately a $100,000 ransom in Bitcoin to receive a decryptor e recover the encrypted files. The Kansas medical center notified the FBI, which investigated the incident and was able to identify the previously unknown Maui ransomware and trace the payment to China-based money launderers.
In April this year, the FBI observed an approximately $120,000 Bitcoin payment into one of the seized cryptocurrency accounts that were identified thanks to the cooperation of the Kansas hospital. These funds were related to the payment of a medical provider in Colorado that was hit by the Maui ransomware
The attacks against Healthcare and Public Health Sector organizations started in May 2021 and government experts observed multiple cases that involved the use of the Maui ransomware.
North Korean nation-state actors used Maui ransomware to encrypt servers providing healthcare services, including electronic health records services, diagnostics services, imaging services, and intranet services.
Indicators of Compromise
- 5b7ecf7e9d0715f1122baf4ce745c5fcd769dee48150616753fec4d6da16e99e
- 45d8ac1ac692d6bb0fe776620371fca02b60cac8db23c4cc7ab5df262da42b78
- 56925a1f7d853d814f80e98a1c4890b0a6a84c83a8eded34c585c98b2df6ab19
- 830207029d83fd46a4a89cd623103ba2321b866428aa04360376e6a390063570
- 458d258005f39d72ce47c111a7d17e8c52fe5fc7dd98575771640d9009385456
- 99b0056b7cc2e305d4ccb0ac0a8a270d3fceb21ef6fc2eb13521a930cea8bd9f
- 3b9fe1713f638f85f20ea56fd09d20a96cd6d288732b04b073248b56cdaef878
- 87bdb1de1dd6b0b75879d8b8aef80b562ec4fad365d7abbc629bcfc1d386afa6