VHD Ransomware

Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:03:41

Targeted industries: energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:kr

Context

VHD Ransomware is a malware family that encrypts files and demands a ransom for their release. It has been notably used in targeted attacks against the energy and telecommunications sectors, particularly in South Korea. The ransomware is suspected to be linked to state-sponsored actors, using double extortion tactics.

Detection coverage

  • 4 YARA rules

Detection rules

  • SEKOIA_Apt_Lazarus_Vhd_Ransomware_Downloader (yara-rule)
  • SEKOIA_Apt_Lazarus_Vhd_Ransomware_Loader (yara-rule)
  • SIGNATURE_BASE_APT_MAL_NK_Lazarus_VHD_Ransomware_Oct20_1 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_NK_Lazarus_VHD_Ransomware_Oct20_2 (yara-rule)

Reports & references

  • Kaspersky — 97937 (report)
  • trellix.com — The Sound Of Malware (report)
  • Kaspersky — 97757 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Vhd Ransomware (report)
  • twitter.com — 1241657443282825217 (report)
  • seguranca-informatica.pt — Secrets Behind The Lazaruss Vhd Ransomware (report)
  • trellix.com — The Hermit Kingdoms Ransomware Play (report)

External references