Worked example · 2021-20
Andariel Maui ransomware — healthcare-sector targeting — 2021–2024
Summary
Andariel has been tracked as a distinct DPRK RGB sub-element since at least the mid-2010s, with the cluster's ransomware-and-cryptocurrency-mining operational pattern crystallising from approximately 2021 onward with the deployment of the Maui ransomware family against healthcare-sector targets.
The July 2022 CISA/FBI/Treasury joint advisory AA22-187A characterised the Maui ransomware operation: Andariel operators deployed Maui against U.S. healthcare and public-health (HPH) sector entities, encrypting systems and demanding Bitcoin-denominated ransom payments. The advisory noted that the HPH-sector targeting was consistent with DPRK state priorities (the DPRK healthcare system was under severe stress during the COVID-19 pandemic) and with the regime's broader cyber-enabled revenue-generation strategy.
The July 2024 DOJ indictment of Rim Jong Hyok named a specific Andariel operator and detailed a multi-year campaign of: (a) healthcare-sector ransomware attacks (Maui); (b) DIB-intrusion espionage against U.S. defence contractors and aerospace entities; (c) cryptocurrency-mining deployments (xmrig) on compromised engineering and manufacturing systems, with mined cryptocurrency routed to DPRK-controlled wallets. The accompanying $10M State Department reward is the largest reward offered for a named DPRK cyber operator.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| ~2017 | Andariel DTrack / pre-Maui intrusion tooling observed; DIB targeting documented | (pre-crypto phase) |
| 2021 | Maui ransomware family deployed; healthcare-sector targeting pattern crystallises | T5.008 |
| 2022-07 | CISA/FBI/Treasury joint advisory AA22-187A — Maui ransomware characterised as DPRK-attributed HPH-sector threat | (attribution milestone) |
| 2024-07 | DOJ indictment of Rim Jong Hyok unsealed; $10M State Department reward announced | (attribution milestone) |
| Continuing | Andariel ransomware and cryptocurrency-mining operations remain active at v0.1 cutoff | (ongoing) |
Public references
- CISA/FBI/Treasury: AA22-187A — North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector, July 6, 2022 (
[cisa2022aa22187a]). - DOJ: indictment of Rim Jong Hyok, July 25, 2024 (
[doj2024rimjonghyok]). - CISA/FBI/NSA/ROK NIS/NPA/DSA/NCSC: joint advisory — North Korea state-sponsored cyber group conducts global espionage campaign, July 25, 2024 (
[cisa2024andarieladvisory]). - OFAC: Lazarus, BlueNoroff, and Andariel SDN designation, September 13, 2019 (
[ofac2019dprkcyber]).