귀신(Gwisin) 랜섬웨어 공격 전략 분석 리포트

2022-08-24 SKShildus Gwisin ransomware attack strategy analysis report

https://www.skshieldus.com/download/files/download.do?o_fname=%EA%B7%80%EC%8B%A0(Gwisin)%20%EB%9E%9C%EC%84%AC%EC%9B%A8%EC%96%B4%20%EA%B3%B5%EA%B2%A9%20%EC%A0%84%EB%9E%B5%20%EB%B6%84%EC%84%9D%20%EB%A6%AC%ED%8F%AC%ED%8A%B8.pdf&r_fname=20220824150111854.pdf

Attachments

download.doo_fnameEAB780EC8BA0Gwisin20EB9E9CEC84ACEC9BA8EC96B420EA_qC0ETLa.pdf (6 MB)

SK Shieldus analyzes the Gwisin ransomware group as a Korea-focused operation that has targeted domestic medical, pharmaceutical, financial, and other enterprises since 2021, with no confirmed foreign victims at the time of reporting. The report maps the operation to a cyber attack lifecycle: reconnaissance through Shodan/Censys and dark-web credential acquisition, initial compromise via exposed services and stolen accounts, foothold establishment, privilege escalation, internal reconnaissance, SMB/SSH/WinRM/WMI lateral movement, C2-based exfiltration, log clearing, and ransomware deployment. It highlights a relatively short average dwell time of about 21 days from initial intrusion to ransomware infection, suggesting organized and rapid operations. The group uses multi-tier extortion around decryption, leaked-data non-sale, and vulnerability-report promises, so defenders are advised to prepare around persistent TTPs rather than unpublished IoCs.

Related Reports

« Back