VHD Ransomware
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:03:41
Targeted industries: energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:kr
Context
VHD Ransomware is a malware family that encrypts files and demands a ransom for their release. It has been notably used in targeted attacks against the energy and telecommunications sectors, particularly in South Korea. The ransomware is suspected to be linked to state-sponsored actors, using double extortion tactics.
Detection coverage
- 4 YARA rules
Detection rules
- SEKOIA_Apt_Lazarus_Vhd_Ransomware_Downloader (yara-rule)
- SEKOIA_Apt_Lazarus_Vhd_Ransomware_Loader (yara-rule)
- SIGNATURE_BASE_APT_MAL_NK_Lazarus_VHD_Ransomware_Oct20_1 (yara-rule)
- SIGNATURE_BASE_APT_MAL_NK_Lazarus_VHD_Ransomware_Oct20_2 (yara-rule)
Reports & references
- Kaspersky — 97937 (report)
- trellix.com — The Sound Of Malware (report)
- Kaspersky — 97757 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Vhd Ransomware (report)
- twitter.com — 1241657443282825217 (report)
- seguranca-informatica.pt — Secrets Behind The Lazaruss Vhd Ransomware (report)
- trellix.com — The Hermit Kingdoms Ransomware Play (report)