Ransom & Dark Web  Issues Week 3, September 2025

Ransom & Dark Web Issues Week 3, September 2025

ASEC Blog publishes Ransom & Dark Web Issues Week 3, September 2025             The emergence of a new ransomware group, BlackShrantac South Korean asset management firms listed as new victims of the Qilin ransomware group A South Korean broadcasting and telecom equipment manufacturer listed as

Kawa4096 Ransomware: Leveraging Brand Mimicry for Psychological Impact

Kawa4096 Ransomware: Leveraging Brand Mimicry for Psychological Impact

In June 2025, a new ransomware group known as Kawa4096 emerged, targeting multinational organizations across various sectors, including finance, education, and services. Their attacks have affected companies in multiple countries, notably Japan and the United States. Although there is currently no public information confirming whether they operate as a Ransomware-as-a-Service (RaaS) or

From El Dorado to BlackLock: Inside a Fast-Rising RaaS Threat

From El Dorado to BlackLock: Inside a Fast-Rising RaaS Threat

BlackLock is a relatively new ransomware group that is believed to have been established around March 2024. Their existence was publicly revealed in June 2024 when the Dedicated Leak Site (DLS) was identified. At that time, information on multiple affected companies had already been posted, suggesting that the gang had

Ransom & Dark Web  Issues Week 2, September 2025

Ransom & Dark Web Issues Week 2, September 2025

ASEC Blog publishes Ransom & Dark Web Issues Week 2, September 2025             Financial Institution Data from Poland and Central Europe Listed for Sale on DarkForums Gunra Ransomware Targets Korean Manufacturer Emergence of Four New Ransomware Groups: Obscura, Yurei, The Gentlemen, Radar     

August 2025 Security Issues in Korean & Global Financial Sector

August 2025 Security Issues in Korean & Global Financial Sector

This report comprehensively covers actual cyber threats and security issues related to financial companies in South Korea and abroad. This article includes an analysis of malware and phishing cases distributed to the financial sector, the top 10 malware strains targeting the financial sector, and the industry statistics of leaked Korean

Trigona Rebranding Suspicions and Global Threats, and BlackNevas Ransomware Analysis

Trigona Rebranding Suspicions and Global Threats, and BlackNevas Ransomware Analysis

BlackNevas has been continuously launching ransomware attacks against companies in various industries and countries, including South Korea. This post provides a technical analysis on the characteristics, encryption methods, and reasons why BlackNevas encrypts files in a way that makes them impossible to decrypt. It is hoped that this post will

CyberVolk Ransomware: Analysis of Double Encryption Structure and Disguised Decryption Logic

CyberVolk Ransomware: Analysis of Double Encryption Structure and Disguised Decryption Logic

The CyberVolk ransomware, which first emerged in May 2024, has been launching attacks on public institutions and key infrastructures of various countries, posing a continuous threat. The ransomware is particularly notable for its pro-Russia nature, as it primarily targets anti-Russian countries, making it a geopolitically significant cyber threat. This post

Ransom & Dark Web  Issues Week 1, Sep. 2025

Ransom & Dark Web Issues Week 1, Sep. 2025

ASEC Blog publishes Ransom & Dark Web Issues Week 1, Sep. 2025           Japan-Based Automotive Company Listed as a New Victim of Ransomware Group Black Nevas Emergence of New Ransomware Groups: Desolator and LunaLock Korean Electronics Parts Manufacturer Targeted by Ransomware Group Gunra  

Dire Wolf Ransomware: Threat Combining Data Encryption and Leak Extortion

Dire Wolf Ransomware: Threat Combining Data Encryption and Leak Extortion

DireWolf Ransomware Group The DireWolf ransomware group made their first appearance in May 2025. On May 26 of the same month, they disclosed their first 6 victims on a darknet leak site, marking the beginning of their full-fledged activities. The group stated that their only goal is money and contacts

Ransom & Dark Web  Issues Week 4, August 2025

Ransom & Dark Web Issues Week 4, August 2025

ASEC Blog publishes Ransom & Dark Web Issues Week 4, August 2025         Qilin Targets Japanese Automotive Design Firm in Ransomware Attack Attempt to Sell South Korean Local Government Data on DarkForums Raises Credibility Concerns Emerging Ransomware Group Cephalus Hits at Least 9 Organizations, Reveals Victims via