Ransom & Dark Web Issues Week 3, September 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 3, September 2026 Internal Data of a Japanese Pharmaceutical and Healthcare Company Offered for Sale Following a Cyber Incident Customer Data of a South Korean E-Commerce and Retail Company Offered for Sale AUDIT TEAM Ransomware Attacks
Private HTS programs that spread ransomware
AhnLab SEcurity intelligence Center (ASEC) recently identified a case in which ransomware was distributed through a private home trading system (HTS). The HTS program used to distribute the ransomware is called “UBP Asset” and has long been exploited in online investment scams. Given that a photo of the same HTS
Ransom & Dark Web Issues Week 2, September 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 2, September 2026 The Gentlemen Ransomware Attack on a Canadian Airline LAPSUS$ Group Resumes Chapter II and Teases New Victim Disclosure AUDIT TEAM Data Extortion Attacks on Four Organizations in South Korea, Germany, and Argentina
Ransom & Dark Web Issues Week 1, September 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026 ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
Ransom & Dark Web Issues Week 4, August 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026 Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations
Ransom & Dark Web Issues Week 2, August 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026. DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
Ransom & Dark Web Issues Week 1, August 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 1, August 2026 South Korean Automotive Parts Manufacturer’s Internal Server Access and Database Offered for Sale Data of a Turkish HR Consulting Company Offered for Sale Gunra Ransomware Attack on a South Korean Heavy Equipment Parts
[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)
This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute

