Korean
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:37:10
Context
Korean is a ransomware variant based on the HiddenTear open-source project. This malware encrypts files on the victim's system and demands a ransom for decryption.
Detection coverage
- 1 YARA rules
Used by threat actors
- Andariel Espionage Activity (campaign)
- Citrine Sleet Chromium Zero-Day Exploit Activity (CVE-2024-7971) (campaign)
- Defense Sector Supply Chain Compromise by North Korea-Linked Actors (campaign)
- Emerald Sleet PowerShell User Execution Activity (campaign)
- Operation Honeybee (campaign)
- TA455 Iranian Dream Job Campaign (campaign)
- Wagemole (campaign)
- 2025 Bluenoroff Cryptocurrency Foundation Targeting (campaign)
Detection rules
- MALPEDIA_Win_Unidentified_013_Korean_Malware_Auto (yara-rule)
Reports & references
- nyxbone.com — Koreanransom (report)
- id-ransomware.blogspot.com — Korean Ransomware (report)