Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 6 actorsExploits 3 CVEs

Maui

Maui is a ransomware family associated with North Korean state-sponsored cyber actors, most consistently linked in the provided content to Lazarus Group and its Andariel/Stonefly/APT45 sub-cluster. U.S. government reporting cited in the content states that DPRK actors have used Maui since at least May 2021, and CISA reported in 2022 that it was used to target the healthcare and public health sector. Multiple references describe Maui as custom-developed or bespoke ransomware historically built and deployed by Lazarus alongside other DPRK-linked ransomware families such as WannaCry and H0lyGh0st. The content also notes reporting that Andariel deployed Maui in at least one 2022 incident and that North Korean-backed Maui actors were tied to multiple cyberattacks against healthcare organizations. Targeting mentioned in the content includes healthcare and public health organizations, with additional references to activity affecting entities in South Korea, Japan, and the United States. The malware is discussed in the context of financially motivated DPRK operations, with joint government advisories stating that ransomware revenue supports broader North Korean state priorities and follow-on cyber operations. No specific Maui technical indicators or file-level IOCs are provided in the content beyond the malware name and its association with DPRK healthcare-sector ransomware activity.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2021-44228Log4ShellExploited in the wild

Recently observed CVEs that actors used to gain access include remote code execution in the Apache Log4j software library (known as Log4Shell)... Observed CVEs used include: CVE-2021-44228

via cisa advisoriescisa.gov
CVE-2022-24990TerraMaster TOS administrative password disclosure via User-Agent headerExploited in the wild

Observed CVEs used include: ... CVE-2022-24990 ... The TerraMaster OS Unauthenticated Remote Command Execution via PHP Object Instantiation Vulnerability is characterized by scanning activity targeting a flaw...

via cisa advisoriescisa.gov
CVE-2021-20038Unauthenticated RCE in SonicWall SMA100 Apache httpd mod_cgiExploited in the wild

Recently observed CVEs that actors used to gain access include ... remote code execution in unpatched SonicWall SMA 100 appliances... Observed CVEs used include: CVE-2021-20038

via cisa advisoriescisa.gov
THREAT ACTORS

Groups observed using it

6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Lazarus

Lazarus Group has historically built its own ransomware -- WannaCry (2017), Maui (2022), H0lyGh0st (2022).

via breakglass intelintel.breakglass.tech
Andariel

Andariel was reported deploying their signature Maui ransomware on at least one occasion in 2022

via sekoia blogblog.sekoia.io
Stonefly/Clasiopa

For more information on this ransomware activity, see... North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector.

via ic3 alertsic3.gov
North Korean state-sponsored cyber actors

"Maui ransomware, which has been used by North Korean state-sponsored cyber actors since at least May 2021 to target Healthcare and Public Health (HPH) Sector organizations."

via cisa alertscisa.gov
Contagious Interview

North Korea has long been involved in ransomware attacks and has been previously associated with the Maui and Play ransomware families.

via ctoatncsc substackctoatncsc.substack.com
DPRK cyber actors

This CSA provides an overview of Democratic People’s Republic of Korea (DPRK) state-sponsored ransomware and updates the July 6, 2022, joint CSA North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector.

via cisa advisoriescisa.gov
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

2 techniques
T1583Acquire InfrastructureEvidence1

"Acquire Infrastructure [ T1583 ] . DPRK actors generate domains, personas, and accounts; and identify cryptocurrency services to conduct their ransomware operations."

T1583.003Virtual Private ServerEvidence1

"Purchase VPNs and VPSs [ T1583.003 ] . DPRK cyber actors will also use virtual private networks (VPNs) and virtual private servers (VPSs) or third-country IP addresses..."

Initial Access

3 techniques
T1133External Remote ServicesEvidence1

"...remote code execution in unpatched SonicWall SMA 100 appliances [T1190 and T1133]."

T1190Exploit Public-Facing ApplicationEvidence3

"The other victim operated a vulnerable Weblogic server... compromised this server via the CVE-2017-10271 exploit." | "In one victim system, we discovered that a well-known simple HTTP server, HFS7, had deployed the malware above. After an unknown exploit was used on a vulnerable HFS server and “whoami” was executed..."

T1195Supply Chain CompromiseEvidence1

"Actors also likely spread malicious code through Trojanized files for “X-Popup,” an open source messenger... [T1195]."

Persistence

1 technique
T1133External Remote ServicesEvidence1

"...remote code execution in unpatched SonicWall SMA 100 appliances [T1190 and T1133]."

Stealth

1 technique
T1070.004File DeletionEvidence1

"“-x” commands the malware to “self melt”"

Discovery

1 technique
T1083File and Directory DiscoveryEvidence1

"...perform reconnaissance activities, upload and download additional files and executables, and execute shell commands [T1083, T1021]."

Lateral Movement

1 technique
T1021Remote ServicesEvidence1

"...perform reconnaissance activities... and execute shell commands [T1083, T1021]."

Impact

1 technique
T1486Data Encrypted for ImpactEvidence12

In 2022, the U.S. Cybersecurity and Infrastructure Security Agency reported on North Korean state-sponsored actors' use of MAUI ransomware to target the healthcare and public health sectors. In 2021, Kaspersky reported on the identification of ransomware tracked by Mandiant as SHATTEREDGLASS, which has been used by suspected APT45 clusters.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution6

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.