한국 기업을 타깃으로 하는 귀신 랜섬웨어 (리눅스 ver)

2022-08-24 Cyberone Ghost ransomware targeting Korean companies (Linux ver)

https://www.cyberone.kr/news-trends-detail?id=92304&page=1

Thumbnail for 한국 기업을 타깃으로 하는 귀신 랜섬웨어 (리눅스 ver)

CyberOne analyzed the Linux version of Gwisin ransomware, a ransomware family reported to target Korean companies and to include victim-specific ransom notes warning against reporting to KISA. The sample stores RC4-encrypted JSON configuration that defines excluded directories, services to terminate, ransom-note names, priority encryption paths, and targeted data locations such as database, web, Docker, and enterprise application directories. Command-line options can shut down ESXi VMs, terminate services, delay execution, encrypt selected paths, include normally excluded ESXi-related files, create marker files, or self-delete after encryption. The malware creates and locks a hardcoded file under /tmp to prevent duplicate execution, changes encrypted file extensions to a victim-specific value, and leaves ransom notes in encrypted directories.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 95237d0c6e6b1822cecca34994c0d273 2022-08-24 2022-11-01
HASH f1bdb5151f24b175d4778052d072061… 2022-08-24 2022-08-24
HASH 89958dbdb557286ad4d6cbf433b7205… 2022-08-24 2022-08-24

Related Reports

« Back