Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Trikon Shakes Hands with ZNS Connect to Simplify Cross-Chain User Identity

June 16, 2026

Summer of crypto (regs): State of Crypto

June 16, 2026

Ethereum Research Proposal Targets Post-Quantum Wallet Security At Low Gas Cost

June 16, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»US Warns Critical Sectors Against North Korean Ransomware Attacks
US Warns Critical Sectors Against North Korean Ransomware Attacks
Security and Privacy

US Warns Critical Sectors Against North Korean Ransomware Attacks

May 29, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

The US Cybersecurity and Infrastructure Security Agency (CISA) issued a new Cybersecurity Advisory (CSA) on Thursday warning critical infrastructure sector entities against ongoing North Korean state-sponsored ransomware activity.

Part of the #StopRansomware campaign, the new advisory is a result of a collaboration between CISA, the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Department of Health and Human Services (HHS), the Republic of Korea (ROK) National Intelligence Service (NIS) and the ROK Defense Security Agency (DSA).

The technical write-up builds on a July advisory, which provided an overview of Democratic People’s Republic of Korea (DPRK) state-sponsored ransomware groups.

The latest iteration of the document is now analyzing activity by the Maui and H0lyGh0st groups. Observable tactics, techniques and procedures (TTPs) mentioned in the CISA advisory include the acquisition of infrastructure, such as domains, personas and accounts, as well as the obfuscation of identities.

These DPRK threat actors reportedly purchased virtual private networks (VPNs) and virtual private servers (VPSs) or third-country IP addresses to hide their location. They used various exploits of common vulnerabilities to gain access and escalate network privileges. These include CVE 2021-44228, CVE-2021-20038 and CVE-2022-24990.

After obtaining initial access, these DPRK cyber actors were observed using staged payloads with customized malware to perform reconnaissance activities and execute shell commands, among other techniques. Privately developed ransomware has been deployed consistently during these campaigns, with ransom demands set in Bitcoin.

To protect against these threats, the CISA advisory advocates several mitigations, such as limiting access to data by authenticating and encrypting connections, utilizing concepts of least privilege in accounts and creating multi-layer defenses for networks and assets.

See also  Upbit Crypto Exchange Suffers 160k Cyber Attacks In Only 6 Months 

According to Roman Arutyunov, co-founder and SVP of products at Xage Security, critical infrastructure providers should embrace these changes despite the technical difficulties associated with such implementations.

“I do recognize that fears exist when it comes to the difficulty of making security architecture changes, but there are tools available to smooth the transition and enhance security and operations simultaneously,” Arutyunov told Infosecurity in an email.

“Ultimately, more threats will come, so it’s wise to start the process now.”

The CISA advisory comes weeks after Proofpoint researchers shed light on a new DPRK cyber actor called TA444.

Source link

attacks Critical Korean North Ransomware Sectors warns
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

South Korean Tech Giant LG Announces Collaboration with an Altcoin!

June 14, 2026

What The FIFA World Cup 2026 Means For Fraud

June 12, 2026

Phunware to Showcase AI-Enabled Guest Intelligence Platform Enhancements at HITEC North America 2026

June 11, 2026

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

June 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

The Fed Must Have Confident Consumers

September 23, 2024

Ethereum NFTs Can Be Migrated to Bitcoin, But There’s a Catch

May 31, 2023

A Big Week For Token Unlocks Could Send Altcoins Prices Deeper

July 18, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Trikon Shakes Hands with ZNS Connect to Simplify Cross-Chain User Identity

June 16, 2026

Summer of crypto (regs): State of Crypto

June 16, 2026

Ethereum Research Proposal Targets Post-Quantum Wallet Security At Low Gas Cost

June 16, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$66,069.000.43%
  • ethereumEthereum(ETH)$1,762.042.49%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$613.55-0.63%
  • rippleXRP(XRP)$1.233.56%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$73.673.54%
  • tronTRON(TRX)$0.317813-0.89%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.27%
  • HyperliquidHyperliquid(HYPE)$71.7310.84%