Ransom & Dark Web  Issues Week 2, September 2025

Ransom & Dark Web Issues Week 2, September 2025

ASEC Blog publishes Ransom & Dark Web Issues Week 2, September 2025             Financial Institution Data from Poland and Central Europe Listed for Sale on DarkForums Gunra Ransomware Targets Korean Manufacturer Emergence of Four New Ransomware Groups: Obscura, Yurei, The Gentlemen, Radar     

Trigona Rebranding Suspicions and Global Threats, and BlackNevas Ransomware Analysis

Trigona Rebranding Suspicions and Global Threats, and BlackNevas Ransomware Analysis

BlackNevas has been continuously launching ransomware attacks against companies in various industries and countries, including South Korea. This post provides a technical analysis on the characteristics, encryption methods, and reasons why BlackNevas encrypts files in a way that makes them impossible to decrypt. It is hoped that this post will

CyberVolk Ransomware: Analysis of Double Encryption Structure and Disguised Decryption Logic

CyberVolk Ransomware: Analysis of Double Encryption Structure and Disguised Decryption Logic

The CyberVolk ransomware, which first emerged in May 2024, has been launching attacks on public institutions and key infrastructures of various countries, posing a continuous threat. The ransomware is particularly notable for its pro-Russia nature, as it primarily targets anti-Russian countries, making it a geopolitically significant cyber threat. This post

Ransom & Dark Web  Issues Week 4, August 2025

Ransom & Dark Web Issues Week 4, August 2025

ASEC Blog publishes Ransom & Dark Web Issues Week 4, August 2025         Qilin Targets Japanese Automotive Design Firm in Ransomware Attack Attempt to Sell South Korean Local Government Data on DarkForums Raises Credibility Concerns Emerging Ransomware Group Cephalus Hits at Least 9 Organizations, Reveals Victims via

Warning About NightSpire Ransomware Following Cases of Damage in South Korea

Warning About NightSpire Ransomware Following Cases of Damage in South Korea

NightSpire operates a DLS (Dedicated Leak Site) and posts a countdown timer for the public release of information and data about victims. The group is known for using highly threatening language for their cyber extortion. This post describes the analysis and characteristics of NightSpire ransomware.   1. Overview 1.1. NightSpire

Interlock Ransomware’s Targeted Attacks on Companies

Interlock Ransomware’s Targeted Attacks on Companies

Summary About Interlock –      Appeared at the end of September 2024 –      Ransomware attacks targeting companies in various countries and industries worldwide –      Recently, there have also been ransomware attacks in various industries such as healthcare, education, and public institutions (e.g., DaVita, Andretti Indoor Karting & Games) –      Uses unclear

Underground Ransomware Targeting Korean Companies

Underground Ransomware Targeting Korean Companies

The Underground ransomware gang is launching continuous ransomware attacks against companies in various countries and industries, including South Korea. This post describes the analysis and characteristics of the Underground ransomware.   1. Overview 1.1 Team Underground The ransomware strain operated by the group known as Underground was first identified in

Ransom & Dark Web  Issues Week 3, August 2025

Ransom & Dark Web Issues Week 3, August 2025

ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2025             WARLOCK launched a ransomware attack targeting a telecommunications provider in France. The pro-Israeli hacktivist group “313 Team” claims to have conducted DDoS attacks against nine institutions in Saudi Arabia. Qilin carried out

Gunra Ransomware Emerges with New DLS

Gunra Ransomware Emerges with New DLS

AhnLab TIP monitors the current ransomware group activities across dark web forums, marketplaces, and other sources. Through the Live View > Dark Web Watch menu, users can track the most active ransomware groups, uncover their collaborations, and gain insights into planned attacks and techniques—enabling user organizations to anticipate threats, prepare

June 2025 Threat Trend Report on Ransomware

June 2025 Threat Trend Report on Ransomware

This report provides statistics on the number of new ransomware samples and affected systems, and affected companies that were collected in June 2025, as well as major ransomware issues in and out of Korea. Below is a summary of the information.   The statistics on the number of ransomware samples