A new ransomware family called ‘GwisinLocker’ was discovered that targets healthcare, industrial, and pharmaceutical companies in South Korea with Windows and Linux encryptors including support for encrypting VMware ESXi servers and virtual machines.
The new malware that was detected by researchers at ReversingLabs is the product of a lesser-known threat actor dubbed Gwisin, which means “ghost” in Korean.
The attack also coincided with Korean public holidays and occurred during early morning hours, which suggests that Gwisin has an idea of the country’s culture and business routines.
The reports about Gwisin and its activities first appeared on South Korean media outlets late last month, when the threat actor compromised large pharmaceutical firms in the country.
Korean cybersecurity experts at Ahnlab published a report on the Windows encryptor, and yesterday, security researchers at ReversingLabs published their technical analysis of the Linux version.
The Gwisin group communicated with its victims and claims to have deep knowledge of their network and said that they exfiltrated data with which to extort the company.
The ransom notes associated with GwisinLocker.Linux contained detailed internal information from the compromised environment, and encrypted files used file extensions customized to use the name of the victim company.
In order to make the ransom payment, the victims must log into a portal operated by the group and establish private communications channels for completing ransom payments.
So not much details about the payment method used and/or cryptocurrency wallets associated with the group are known.
Because of familiarity with the Korean language as well as with the South Korean government and law enforcement forces, it is speculated that Gwisin may be a North Korean-linked advanced persistent threat (APT) group.
This threat should be of particular concern to industrial and pharmaceutical companies in South Korea.
The security researchers warns the firms concerned with GwisinLocker to review the Indicators of Compromise in the report and make them available to internal or external threat hunting teams.
Image Credits : Euractiv

















Comments