Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

LAB records 40% hike to hit record highs – Are buybacks driving demand?

June 3, 2026

European cloud providers back EU push to cut reliance on US tech giants

June 3, 2026

Ajay Rajan joins Protean eGov Technologies Ltd. as Managing Director & Chief Executive Officer

June 3, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»GwisinLocker Ransomware Targets Linux Systems in South Korea
GwisinLocker Ransomware Targets Linux Systems in South Korea
Security and Privacy

GwisinLocker Ransomware Targets Linux Systems in South Korea

June 16, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

ReversingLabs researchers discovered a new ransomware family targeting Linux-based systems in South Korea.

Dubbed GwisinLocker, the malware was detected by ReversingLabs on July 19 while undertaking successful campaigns targeting firms in the industrial and pharmaceutical space.

“In those incidents, it often launched attacks on public holidays and during the early morning hours (Korean time) – looking to take advantage of periods in which staffing and monitoring within target environments were relaxed,” ReversingLabs wrote in an advisory published on Thursday.

In the document, the company claimed GwisinLocker is a new malware variant created by a previously little-known threat actor (TA) called “Gwisin” (a Korean term for ‘ghost’ or ‘spirit’).

“In communications with its victims, the Gwisin group claims to have deep knowledge of their network and claim that they exfiltrated data with which to extort the company,” ReversingLabs said.

Additionally, ransom notes associated with GwisinLocker.Linux contained detailed internal information from the compromised environment, and encrypted files used file extensions customized to use the name of the victim company. 

Regarding details of the payment system behind the ransomware, ReversingLabs said GwisinLocker.Linux victims are required to log into a portal operated by the group and establish private communications channels for completing ransom payments. 

“As a result, little is known about the payment method used and/or cryptocurrency wallets associated with the group.”

Because of familiarity with the Korean language as well as with the South Korean government and law enforcement forces, ReversingLabs said Gwisin may be a North Korean-linked advanced persistent threat (APT) group. 

“This threat should be of particular concern to industrial and pharmaceutical companies in South Korea, which account for the bulk of Gwisin’s victims to date,” ReversingLabs explained.

See also  South Korea to regulate cross-border crypto trades by 2025

“However, it is reasonable to assume that this threat actor may expand its campaigns to organizations in other sectors, or even outside of South Korea.”

The security researchers concluded the advisory by warning firms concerned with GwisinLocker to review the Indicators of Compromise in the report and make them available to internal or external threat hunting teams.

Source link

GwisinLocker Korea Linux Ransomware South Systems Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Georgia targets illegal crypto mining with new electricity meters in Mestia

June 2, 2026

South Korea opens reporting period for 2025 overseas financial accounts

June 2, 2026

Crypto News Today: AlphaPepe Hits $1.38M Raised While Bitcoin Price Prediction Targets $250K

May 31, 2026

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Insillion Partners with Profinch to Deliver a Unified Insurance Solution Powered by Oracle’s Insurance Policy Administration (OIPA)

April 8, 2026

Fire Alarm at Australian Crypto Summit Strikes Symbolic Note After ASIC Regulator’s Comment

September 25, 2024

‘Backdoor blacklisting function’ – TRON’s Justin Sun escalates WLFI feud

April 13, 2026

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

LAB records 40% hike to hit record highs – Are buybacks driving demand?

June 3, 2026

European cloud providers back EU push to cut reliance on US tech giants

June 3, 2026

Ajay Rajan joins Protean eGov Technologies Ltd. as Managing Director & Chief Executive Officer

June 3, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$67,169.00-4.19%
  • ethereumEthereum(ETH)$1,876.80-5.42%
  • tetherTether(USDT)$1.000.02%
  • binancecoinBNB(BNB)$643.89-5.80%
  • rippleXRP(XRP)$1.24-1.74%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$75.11-5.81%
  • tronTRON(TRX)$0.333140-1.98%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.04-0.61%
  • HyperliquidHyperliquid(HYPE)$72.330.39%