Maui ransomware

First seen
2021-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:12:09

Targeted industries: healthcare-and-pharmaceutical

Context

Maui ransomware stand out because of a lack of several key features commonly seen with tooling from RaaS providers, such as an embedded ransom note to provide recovery instructions or automated means of transmitting encryption keys to attackers. Instead, it is believed that Maui is manually operated, in which operators will specify which files to encrypt when executing it and then exfiltrate the resulting runtime artifacts. There are many aspects to Maui ransomware that are unknown, including usage context.

Reports & references

  • CISA — Aa23 040A (report)
  • stairwell.com — Stairwell Threat Report Maui Ransomware (report)
  • CISA — Aa22 187A (report)
  • Kaspersky — 107063 (report)
  • media.defense.gov — Csa Ransomware Attacks On Ci Fund Dprk Activities (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Maui (report)
  • CISA — Aa22 187A North Korean%20State Sponsored Cyber Actors Use Maui Ransomware To Target The Hph Sector (report)

External references