June 6, 2023

The U.S. DoJ has seized $500,000 worth of Bitcoin from North Korean threat actors who used the Maui ransomware to target several organizations worldwide.

A complaint filed in the District of Kansas to forfeit cryptocurrency paid as ransom to North Korean hackers or otherwise used to launder such ransom payments. The seized funds include ransoms paid by health care providers in Kansas and Colorado.


Maui ransomware infected the servers of the hospital in the District of Kansas. They opted to pay approximately a $100,000 ransom in Bitcoin to receive a decryptor e recover the encrypted files. The Kansas medical center notified the FBI, which investigated the incident and was able to identify the previously unknown Maui ransomware and trace the payment to China-based money launderers.

In April this year, the FBI observed an approximately $120,000 Bitcoin payment into one of the seized cryptocurrency accounts that were identified thanks to the cooperation of the Kansas hospital. These funds were related to the payment of a medical provider in Colorado that was hit by the Maui ransomware

The attacks against Healthcare and Public Health Sector organizations started in May 2021 and government experts observed multiple cases that involved the use of the Maui ransomware.

North Korean nation-state actors used Maui ransomware to encrypt servers providing healthcare services, including electronic health records services, diagnostics services, imaging services, and intranet services.


Indicators of Compromise

  • 5b7ecf7e9d0715f1122baf4ce745c5fcd769dee48150616753fec4d6da16e99e
  • 45d8ac1ac692d6bb0fe776620371fca02b60cac8db23c4cc7ab5df262da42b78
  • 56925a1f7d853d814f80e98a1c4890b0a6a84c83a8eded34c585c98b2df6ab19
  • 830207029d83fd46a4a89cd623103ba2321b866428aa04360376e6a390063570
  • 458d258005f39d72ce47c111a7d17e8c52fe5fc7dd98575771640d9009385456
  • 99b0056b7cc2e305d4ccb0ac0a8a270d3fceb21ef6fc2eb13521a930cea8bd9f
  • 3b9fe1713f638f85f20ea56fd09d20a96cd6d288732b04b073248b56cdaef878
  • 87bdb1de1dd6b0b75879d8b8aef80b562ec4fad365d7abbc629bcfc1d386afa6

Leave a Reply

%d bloggers like this: