Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

XRP 2017 Breakout Replay? Analyst Drops Bold 1,992% Target

May 1, 2026

From Cathie Wood to Cantor Fitzgerald, the big money is betting that Robinhood’s (HOOD) crypto slump is just a temporary speed bump

May 1, 2026

Invisible NFTs Explained: Hidden Metadata, Secret NFTs & Reveal Mechanics

May 1, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»US Warns Critical Sectors Against North Korean Ransomware Attacks
US Warns Critical Sectors Against North Korean Ransomware Attacks
Security and Privacy

US Warns Critical Sectors Against North Korean Ransomware Attacks

May 29, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

The US Cybersecurity and Infrastructure Security Agency (CISA) issued a new Cybersecurity Advisory (CSA) on Thursday warning critical infrastructure sector entities against ongoing North Korean state-sponsored ransomware activity.

Part of the #StopRansomware campaign, the new advisory is a result of a collaboration between CISA, the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Department of Health and Human Services (HHS), the Republic of Korea (ROK) National Intelligence Service (NIS) and the ROK Defense Security Agency (DSA).

The technical write-up builds on a July advisory, which provided an overview of Democratic People’s Republic of Korea (DPRK) state-sponsored ransomware groups.

The latest iteration of the document is now analyzing activity by the Maui and H0lyGh0st groups. Observable tactics, techniques and procedures (TTPs) mentioned in the CISA advisory include the acquisition of infrastructure, such as domains, personas and accounts, as well as the obfuscation of identities.

These DPRK threat actors reportedly purchased virtual private networks (VPNs) and virtual private servers (VPSs) or third-country IP addresses to hide their location. They used various exploits of common vulnerabilities to gain access and escalate network privileges. These include CVE 2021-44228, CVE-2021-20038 and CVE-2022-24990.

After obtaining initial access, these DPRK cyber actors were observed using staged payloads with customized malware to perform reconnaissance activities and execute shell commands, among other techniques. Privately developed ransomware has been deployed consistently during these campaigns, with ransom demands set in Bitcoin.

To protect against these threats, the CISA advisory advocates several mitigations, such as limiting access to data by authenticating and encrypting connections, utilizing concepts of least privilege in accounts and creating multi-layer defenses for networks and assets.

See also  US Justice Department charges two men in Mt. Gox hack

According to Roman Arutyunov, co-founder and SVP of products at Xage Security, critical infrastructure providers should embrace these changes despite the technical difficulties associated with such implementations.

“I do recognize that fears exist when it comes to the difficulty of making security architecture changes, but there are tools available to smooth the transition and enhance security and operations simultaneously,” Arutyunov told Infosecurity in an email.

“Ultimately, more threats will come, so it’s wise to start the process now.”

The CISA advisory comes weeks after Proofpoint researchers shed light on a new DPRK cyber actor called TA444.

Source link

attacks Critical Korean North Ransomware Sectors warns
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Defillama Confirms April 2026 as Crypto’s Most-Hacked Month With 30 Incidents

May 1, 2026

North Korea Hit Twice And Snagged 76% Of 2026 Hack Value

April 30, 2026

Japan tells real estate and crypto sectors to tighten AML checks on property deals

April 30, 2026

Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

April 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Genesis settles with New York DFS, will forfeit BitLicense and pay $8 million fine: Fortune

January 14, 2024

US Senator Introduces Crypto Bill Blocking Federal Bailouts for Digital Assets

March 24, 2026

MicroStrategy issues $500M in convertible notes to buy more Bitcoin

June 13, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

XRP 2017 Breakout Replay? Analyst Drops Bold 1,992% Target

May 1, 2026

From Cathie Wood to Cantor Fitzgerald, the big money is betting that Robinhood’s (HOOD) crypto slump is just a temporary speed bump

May 1, 2026

Invisible NFTs Explained: Hidden Metadata, Secret NFTs & Reveal Mechanics

May 1, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$77,027.001.74%
  • ethereumEthereum(ETH)$2,277.861.40%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.370.40%
  • binancecoinBNB(BNB)$616.760.18%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$83.851.18%
  • tronTRON(TRX)$0.3263230.72%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.24%
  • dogecoinDogecoin(DOGE)$0.1085002.26%