Maui is a custom-developed ransomware family used by North Korean state-sponsored cyber actors to encrypt victim data and extort payments. It is associated with Andariel, a North Korea-linked intrusion group commonly tracked within the broader Lazarus ecosystem. Maui attacks have targeted healthcare and public health organizations since at least May 2021, including U.S. hospitals and healthcare companies.
Maui is used in financially motivated operations intended to generate illicit revenue. U.S. and South Korean authorities assess that proceeds from DPRK ransomware operations support North Korean national priorities, including further cyber operations. Maui is distinct from H0lyGh0st, another privately developed ransomware family used in North Korea-linked campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently observed CVEs that actors used to gain access include remote code execution in the Apache Log4j software library (known as Log4Shell)... Observed CVEs used include: CVE-2021-44228
Observed CVEs used include: ... CVE-2022-24990 ... The TerraMaster OS Unauthenticated Remote Command Execution via PHP Object Instantiation Vulnerability is characterized by scanning activity targeting a flaw...
Recently observed CVEs that actors used to gain access include ... remote code execution in unpatched SonicWall SMA 100 appliances... Observed CVEs used include: CVE-2021-20038
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A notable trend is the continued use of ransomware attacks, such as those leveraging Maui ransomware, to generate illicit revenue.
Andariel est notable pour l’utilisation des ransomwares personnalisés Maui et H0lyGh0st, ainsi que du RaaS Play en 2024.
Lazarus Group has historically built its own ransomware -- WannaCry (2017), Maui (2022), H0lyGh0st (2022).
For more information on this ransomware activity, see... North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector.
North Korea has long been involved in ransomware attacks and has been previously associated with the Maui and Play ransomware families.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
"...remote code execution in unpatched SonicWall SMA 100 appliances [T1190 and T1133]."
"The other victim operated a vulnerable Weblogic server... compromised this server via the CVE-2017-10271 exploit." | "In one victim system, we discovered that a well-known simple HTTP server, HFS7, had deployed the malware above. After an unknown exploit was used on a vulnerable HFS server and “whoami” was executed..."
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom ransomware used by the North Korean-linked Andariel group.
Custom ransomware used by Andariel for financially motivated theft.
Ransomware family previously deployed by Andariel, mentioned as background context.
Ransomware used against healthcare organizations, attributed in the content to North Korean state-sponsored actors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.