Storm-0530__2023__CSA_RANSOMWARE_ATTACKS_ON_CI_FUND_DPRK_ACTIVITIES.PDF.pdf
ID: 9b02dc10-e42c-457c-92e3-5e3f37825898
STIX ID: report--9b02dc10-e42c-457c-92e3-5e3f37825898
Threat Score
75/100
Uploaded: 2026-08-20
Published Date: 2023-02-24
Last Modified Date: 2023-02-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
A joint Cybersecurity Advisory describes DPRK state-sponsored ransomware activity targeting U.S. healthcare/public health and critical infrastructure sectors, detailing observed tactics from initial access through data exfiltration, listing associated IOCs and CVEs (including CVE-2021-44228, CVE-2021-20038, CVE-2022-24990), and offering MITRE ATT&CK mappings and CP G-aligned mitigations such as backup hygiene, patch management, RDP hardening, phishing-resistant MFA, incident response planning, and reporting guidance.
