Ransomware

GwisinLocker ransomware targets firms in South Korea

0

A new ransomware family called ‘GwisinLocker’ was discovered that targets healthcare, industrial, and pharmaceutical companies in South Korea with Windows and Linux encryptors including support for encrypting VMware ESXi servers and virtual machines.

The new malware that was detected by researchers at ReversingLabs is the product of a lesser-known threat actor dubbed Gwisin, which means “ghost” in Korean.

The attack also coincided with Korean public holidays and occurred during early morning hours, which suggests that Gwisin has an idea of the country’s culture and business routines.

The reports about Gwisin and its activities first appeared on South Korean media outlets late last month, when the threat actor compromised large pharmaceutical firms in the country.

Korean cybersecurity experts at Ahnlab published a report on the Windows encryptor, and yesterday, security researchers at ReversingLabs published their technical analysis of the Linux version.

The Gwisin group communicated with its victims and claims to have deep knowledge of their network and said that they exfiltrated data with which to extort the company.

The ransom notes associated with GwisinLocker.Linux contained detailed internal information from the compromised environment, and encrypted files used file extensions customized to use the name of the victim company.

In order to make the ransom payment, the victims must log into a portal operated by the group and establish private communications channels for completing ransom payments.

So not much details about the payment method used and/or cryptocurrency wallets associated with the group are known.

Because of familiarity with the Korean language as well as with the South Korean government and law enforcement forces, it is speculated that Gwisin may be a North Korean-linked advanced persistent threat (APT) group.

This threat should be of particular concern to industrial and pharmaceutical companies in South Korea.

The security researchers warns the firms concerned with GwisinLocker to review the Indicators of Compromise in the report and make them available to internal or external threat hunting teams.

Image Credits : Euractiv

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

UK NHS suffers outage due to cyberattack

Previous article

North Korean hackers lure crypto experts with fake job offers

Next article

You may also like

More in Ransomware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *