BlackMoon

First seen
2014-06-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-22 02:59:06
Profile updated
2026-07-07 15:48:30

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Targeted regions: country_code:kr

Context

BlackMoon is a ransomware family known for targeting South Korean users, particularly within the financial services and telecommunications sectors. It encrypts victim's files and demands a ransom for decryption.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Blackmoon (yara-rule)