25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Lazarus Group Actively Exploiting ManageEngine Vulnerability in Attacks on Healthcare Organizations

Healthcare organizations in the United States have been warned that a vulnerability in Zoho’s ManageEngine products is being actively exploited by the North Korean state-sponsored threat actor, the Lazarus Group.

The vulnerability is tracked as CVE-2022-47966 and affects 24 ManageEngine products. The vulnerability can be exploited if SAML single-sign-on is enabled or has ever been enabled in a vulnerable ManageEngine product. Successful exploitation of the flaw allows a threat actor to remotely execute code.

The Lazarus Group has been exploiting the vulnerability to deliver a remote access trojan (RAT) called QuiteRAT, which is believed to be the successor of MagicRAT. Some attacks have seen a new malware tool deployed called CollectionRAT. Both of these malware variants allow the threat actor to perform a range of actions, including arbitrary command injection. According to researchers at Cisco Talos, the Lazarus Group has been targeting Internet backbone infrastructure and healthcare organizations in Europe and the United States since February, with the first attacks starting within 5 days of a proof-of-concept exploit being published.

Zoho released patches for all affected products in October 2022 and recommended immediate patching. CISA added the vulnerability to its  Known Exploited Vulnerabilities Catalog in January 2023; however, many organizations have been slow to patch.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The Health Sector Cybersecurity Coordination Center has published Indicators of Compromise (IoCs) in a September 18, 2023, Sector Alert and strongly encourages all healthcare organizations to ensure that they are running the most recent ManageEngine version.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist