한국 기업을 타깃으로 하는 귀신 랜섬웨어 (리눅스 ver)
2022-08-24 • Cyberone • Ghost ransomware targeting Korean companies (Linux ver) •
CyberOne analyzed the Linux version of Gwisin ransomware, a ransomware family reported to target Korean companies and to include victim-specific ransom notes warning against reporting to KISA. The sample stores RC4-encrypted JSON configuration that defines excluded directories, services to terminate, ransom-note names, priority encryption paths, and targeted data locations such as database, web, Docker, and enterprise application directories. Command-line options can shut down ESXi VMs, terminate services, delay execution, encrypt selected paths, include normally excluded ESXi-related files, create marker files, or self-delete after encryption. The malware creates and locks a hardcoded file under /tmp to prevent duplicate execution, changes encrypted file extensions to a victim-specific value, and leaves ransom notes in encrypted directories.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 95237d0c6e6b1822cecca34994c0d273 | 2022-08-24 | 2022-11-01 |
| HASH | f1bdb5151f24b175d4778052d072061… | 2022-08-24 | 2022-08-24 |
| HASH | 89958dbdb557286ad4d6cbf433b7205… | 2022-08-24 | 2022-08-24 |