Shujin
Aliases: KinCrypt
- First seen
- 2021-05-10 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 15:43:12
Targeted industries: financial-services healthcare-and-pharmaceutical energy-and-utilities
Targeted regions: country_code:us country_code:ca
Context
Shujin, also known as KinCrypt, is a ransomware family known for encrypting files on the victim's machine and demanding a ransom payment for decryption. It primarily targets organizations in critical sectors such as finance, healthcare, and utilities.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Shujin_Auto (yara-rule)
Reports & references
- nyxbone.com — Chineseransom (report)
- Trend Micro — Chinese Language Ransomware Makes Appearance (report)
- id-ransomware.blogspot.com — Chinese Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Shujin (report)
- Trend Micro — Chinese Language Ransomware Makes Appearance (report)