Warning: North Korean Lazarus Group Exploiting ManageEngine Vulnerability, Targeting Healthcare Sector

Federal authorities have issued a warning about the “significant risk” of potential attacks on healthcare and public health sector entities by the North Korean state-sponsored Lazarus Group. These cybercriminals have been targeting the healthcare industry by exploiting a critical vulnerability in 24 ManageEngine IT management tools from Zoho.

Alert details

The U.S. Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HHS HC3) has recently released an alert regarding the activities of the Lazarus Group. This cybercriminal group has been focusing its attacks on internet backbone infrastructure and healthcare entities in Europe and the United States.

The vulnerability that is being exploited by the Lazarus Group is referred to as CVE-2022-47966. This critical vulnerability enables the attackers to gain unauthorized access and control over the ManageEngine software.

Vulnerability exploitation

The vulnerability tracked as CVE-2022-47966 can be exploited if the SAML (Security Assertion Markup Language) single sign-on is or has ever been enabled in the ManageEngine setup. This weakness allows attackers to deploy the remote access Trojan QuiteRAT, which gives them remote control over the compromised systems.

Connection to the Lazarus Group

According to HHS HC3, the attackers are using a remote access Trojan called QuiteRAT, which is believed to be connected to the Jupiter/EarlyRAT malware family. This malware family has been previously associated with the Lazarus Group’s subgroup known as Andariel. These connections strengthen the evidence linking these attacks to the Lazarus Group.

Recognition by authorities

The Cybersecurity and Infrastructure Security Agency (CISA) has added the CVE-2022-47966 flaw to its catalog of known exploited vulnerabilities, highlighting the seriousness of the vulnerability. In September, CISA and the Federal Bureau of Investigation (FBI) jointly released a bulletin warning of nation-state-sponsored actors exploiting this specific vulnerability in ManageEngine.

Previous reports on the vulnerability

Security researchers at Cisco Talos have been tracking the evolving threats posed by the Lazarus Group. In an August blog post, they highlighted the impact of the ManageEngine CVE-2022-47966 vulnerability. This vulnerability has gained attention due to its exploitation by the Lazarus Group in their targeted attacks.

Additionally, Caitlin Condon, the head of vulnerability research at security firm Rapid7, points out that various ManageEngine vulnerabilities have been exploited by different threat actors in the past several years. This indicates the ongoing challenges faced by healthcare and public health sector entities regarding their cybersecurity posture.

Overall threat landscape

The healthcare and public health sector entities are facing numerous serious threat actors, as emphasized by Caitlin Condon. These entities have become prime targets for cybercriminals due to the sensitive and valuable data they possess. Moreover, the reliance on interconnected systems and the rise of remote work in the healthcare sector have further increased their vulnerability to cyberattacks.

The warning from federal authorities regarding the Lazarus Group’s exploitation of the ManageEngine vulnerability is a crucial reminder of the need for robust cybersecurity measures in the healthcare and public health sector. Ongoing vigilance, prompt patch management, and the adoption of best practices are essential to protect against evolving cyber threats. It is vital for healthcare organizations and entities to collaborate with cybersecurity experts and government agencies to stay updated and better defend against sophisticated threat actors like the Lazarus Group.

Explore more

AMD Hikes Radeon RX 9000 GPU Prices by Up to 20%

The long-standing perception of the personal computer as a bastion for performance-driven value has suffered a significant blow as market leaders push prices toward unprecedented heights. This tectonic shift in the hardware landscape signifies the end of an era where premium graphics performance remained within reach of the average consumer. As the third quarter of 2026 unfolds, the sudden surge

Magnora and Blix to Develop New AI Data Center in Oslo

The Evolution of Digital Infrastructure and the Rise of Specialized AI Facilities The intersection of power-hungry artificial intelligence and sustainable urban planning is forcing a radical reimagining of how modern cities utilize their historical industrial footprints. Renewable energy capital is merging with digital infrastructure as legacy systems struggle to keep pace with modern data demands. The Magnora and Blix partnership

New Assets and Legacy Tokens Lead the 2026 Meme Coin Market

The metamorphosis of the cryptocurrency market from a playground for internet subcultures into a sophisticated arena for institutional-grade speculation has reached a pivotal juncture in August 2026. This era is defined by a clear split between legacy tokens that provide market stability and new, high-growth presale assets that offer structured entry points. This transition highlights how the sector has moved

AI-Driven Software Engineering – Review

The traditional image of a developer hunched over a keyboard typing complex syntax is rapidly fading as the industry undergoes a definitive transition from manual coding to intentional oversight. For decades, the field moved incrementally from the esoteric binary of machine code to increasingly abstract languages that mirrored human thought processes more closely. This evolution has culminated in a landscape

Celona Launches Orion to Unify Wi-Fi 7 and Private 5G

The persistent tension between unlicensed Wi-Fi networks and licensed cellular infrastructure has long plagued industrial environments where seamless connectivity is a non-negotiable requirement for operational success. In these high-stakes settings, even a momentary lapse in signal handoff between a mobile robot and a fixed access point can lead to costly downtime or safety hazards on a busy factory floor. Celona