Security News > 2023 > February > North Korea targets US, South Korean hospitals with ransomware to fund further cyber operations

US and South Korean agencies have issued a joint cybersecurity advisory describing the tactics, techniques and procedures used by North Korean hackers to deploy "State-sponsored" ransomware on hospitals and other organizations that can be considered part of the countries' critical infrastructure.
"The authoring agencies assess that an unspecified amount of revenue from these cryptocurrency operations supports DPRK national-level priorities and objectives, including cyber operations targeting the United States and South Korea governments-specific targets include Department of Defense Information Networks and Defense Industrial Base member networks," the advisory points out.
Simultaneously, South Korea imposed sanctions on four North Korean individuals and seven entities for their involvement in these and other state-sanctioned cybercrimes, the proceeds of which are used to fund North Korean nuclear and military programs.
The attackers' TTPs. These North Korean threat actors generate domains, personas, and accounts and pay for them with stolen cryptocurrency or cryptocurrency received as ransom for encrypted data, the agencies say.
Operational mistakes occasionally give them away: In a recently documented campaign targeting public and private sector research organizations and the medical research and energy sector, for example, researchers found one of the webshells connecting to a North Korean state internet IP address.
Mandiant Threat Intelligence head John Hultquist noted on Thursday that several hospitals have had to weather major disruptions due to to this North Korean campaign, and that much of this activity has been obscured because "Hospitals pay or quietly repair and few report."
News URL
Related news
- US govt says North Korea stole over $659 million in crypto last year (source)
- US charges operators of cryptomixers linked to ransomware gangs (source)
- Crypto klepto North Korea stole $659M over just 5 heists last year (source)
- All your 8Base are belong to us: Ransomware crew busted in global sting (source)
- I'm a security expert, and I almost fell for a North Korea-style deepfake job applicant …Twice (source)
- US sanctions LockBit ransomware’s bulletproof hosting provider (source)
- US indicts 8Base ransomware operators for Phobos encryption attacks (source)
- North Korea targets crypto developers via NPM supply chain attack (source)
- US newspaper publisher uses linguistic gymnastics to avoid saying its outage was due to ransomware (source)