Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Alcoa to cash in on crypto’s thirst for energy

April 19, 2026

Ripple Exec Slams Anti-Crypto Documentary Directed by ‘The O.C.’ Star

April 19, 2026

Allor Network Joins Forces With Band Protocol To Enhance AI Web3 Applications With Decentralized Oracle

April 19, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»GwisinLocker Ransomware Targets Linux Systems in South Korea
GwisinLocker Ransomware Targets Linux Systems in South Korea
Security and Privacy

GwisinLocker Ransomware Targets Linux Systems in South Korea

June 16, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

ReversingLabs researchers discovered a new ransomware family targeting Linux-based systems in South Korea.

Dubbed GwisinLocker, the malware was detected by ReversingLabs on July 19 while undertaking successful campaigns targeting firms in the industrial and pharmaceutical space.

“In those incidents, it often launched attacks on public holidays and during the early morning hours (Korean time) – looking to take advantage of periods in which staffing and monitoring within target environments were relaxed,” ReversingLabs wrote in an advisory published on Thursday.

In the document, the company claimed GwisinLocker is a new malware variant created by a previously little-known threat actor (TA) called “Gwisin” (a Korean term for ‘ghost’ or ‘spirit’).

“In communications with its victims, the Gwisin group claims to have deep knowledge of their network and claim that they exfiltrated data with which to extort the company,” ReversingLabs said.

Additionally, ransom notes associated with GwisinLocker.Linux contained detailed internal information from the compromised environment, and encrypted files used file extensions customized to use the name of the victim company. 

Regarding details of the payment system behind the ransomware, ReversingLabs said GwisinLocker.Linux victims are required to log into a portal operated by the group and establish private communications channels for completing ransom payments. 

“As a result, little is known about the payment method used and/or cryptocurrency wallets associated with the group.”

Because of familiarity with the Korean language as well as with the South Korean government and law enforcement forces, ReversingLabs said Gwisin may be a North Korean-linked advanced persistent threat (APT) group. 

“This threat should be of particular concern to industrial and pharmaceutical companies in South Korea, which account for the bulk of Gwisin’s victims to date,” ReversingLabs explained.

See also  Vitalik Buterin addresses ZKasino's misuse of 'zero-knowledge' in $33M scam

“However, it is reasonable to assume that this threat actor may expand its campaigns to organizations in other sectors, or even outside of South Korea.”

The security researchers concluded the advisory by warning firms concerned with GwisinLocker to review the Indicators of Compromise in the report and make them available to internal or external threat hunting teams.

Source link

GwisinLocker Korea Linux Ransomware South Systems Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Crypto News: AlphaPepe AI DEX Demo Over 1000 Users Whilst XRP Price Prediction Targets $5.00 Following Official SEC Commodity Status

April 19, 2026

Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

April 16, 2026

Bank of Korea nominee backs central bank-led digital currency, sees limited role for stablecoins

April 15, 2026

How Lighter DEX targets RWA liquidity gap with $250K weekly incentives

April 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Binance US and CoinMarketCap face renewed class-action in alleged Hex token manipulation

August 13, 2024

Silk Road seller linked to 8,100 bitcoin seizure pleads guilty

January 30, 2024

MiCA delistings will catalyse stronger European crypto offerings

October 21, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Alcoa to cash in on crypto’s thirst for energy

April 19, 2026

Ripple Exec Slams Anti-Crypto Documentary Directed by ‘The O.C.’ Star

April 19, 2026

Allor Network Joins Forces With Band Protocol To Enhance AI Web3 Applications With Decentralized Oracle

April 19, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$75,495.00-2.14%
  • ethereumEthereum(ETH)$2,332.32-3.26%
  • tetherTether(USDT)$1.000.02%
  • rippleXRP(XRP)$1.43-2.56%
  • binancecoinBNB(BNB)$623.33-3.27%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$85.61-3.28%
  • tronTRON(TRX)$0.3293290.58%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.041.31%
  • dogecoinDogecoin(DOGE)$0.094892-3.98%