North Korea-backed hackers target healthcare

Hackers sponsored by North Korea’s government have been using the Maui ransomware to target healthcare and public health services providers for the last year, according to the U.S. government.

Advertisement

The FBI, Cybersecurity and Infrastructure Security Agency, and Treasury Department released a joint statement July 6 with new information about the ransomware, which began hitting U.S. healthcare organizations in May 2021.

Four details:

1. Maui ransomware, known as maui.exe, is an encryption binary designed for manual execution by a remote actor using command-line interface to identify files to encrypt.

2. The ransomware encrypts files with advanced inception standard 128-bit encryption, and each file has a unique AES key and custom header, according to the report.

3. The FBI said it thinks the hackers are using the ransomware against healthcare and public health services providers because organizations are willing to pay the ransom to retrieve their files.

3. Hospitals and health systems can implement and enforce multilayer network segmentation; turn off network device management interfaces; and limit access to data to lessen the severity of the attacks.

 

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

What clinicians need from AI after the pilot: Lessons from Adventist Health and Rady Children’s

Friday, July 24
12:00 PM - 1:00 PM CDT

Presenters: Dr. Dieter Sumerauer, Rady Children’s HealthDr. Salman Naqvi, AdventistDr. Reid Conant, Abridge

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.