Korean

Malware type
ransomware
Profile updated
2026-07-07 13:37:10

Context

Korean is a ransomware variant based on the HiddenTear open-source project. This malware encrypts files on the victim's system and demands a ransom for decryption.

Detection coverage

  • 1 YARA rules

Used by threat actors

  • Andariel Espionage Activity (campaign)
  • Citrine Sleet Chromium Zero-Day Exploit Activity (CVE-2024-7971) (campaign)
  • Defense Sector Supply Chain Compromise by North Korea-Linked Actors (campaign)
  • Emerald Sleet PowerShell User Execution Activity (campaign)
  • Operation Honeybee (campaign)
  • TA455 Iranian Dream Job Campaign (campaign)
  • Wagemole (campaign)
  • 2025 Bluenoroff Cryptocurrency Foundation Targeting (campaign)

Detection rules

  • MALPEDIA_Win_Unidentified_013_Korean_Malware_Auto (yara-rule)

Reports & references

  • nyxbone.com — Koreanransom (report)
  • id-ransomware.blogspot.com — Korean Ransomware (report)

External references