South Korea’s financial industry was struck by a coordinated supply chain attack linked to Russian and North Korean threat actors, which resulted in the deployment of Qilin ransomware and the theft of sensitive data, cybersecurity firm Bitdefender confirmed. When compiling research for its Threat Debrief October report, Bitdefender said it started investigating the campaign after […]South Korea’s financial industry was struck by a coordinated supply chain attack linked to Russian and North Korean threat actors, which resulted in the deployment of Qilin ransomware and the theft of sensitive data, cybersecurity firm Bitdefender confirmed. When compiling research for its Threat Debrief October report, Bitdefender said it started investigating the campaign after […]

South Korea’s financial industry hit in large-scale attack linked to Russian and North Korean hackers

2025/11/27 19:15
4 min read
For feedback or concerns regarding this content, please contact us at [email protected]

South Korea’s financial industry was struck by a coordinated supply chain attack linked to Russian and North Korean threat actors, which resulted in the deployment of Qilin ransomware and the theft of sensitive data, cybersecurity firm Bitdefender confirmed.

When compiling research for its Threat Debrief October report, Bitdefender said it started investigating the campaign after noticing an unusual surge in ransomware incidents in South Korea in September. 

The country recorded 25 attacks that month, a profound difference from the monthly average of only two cases recorded between September 2024 and August this year. 

South Korea targeted in Qilin ransomware attacks

According to Bitdefender’s report published last Monday, South Korea has become the second-most affected country by ransomware this year, trailing the United States only. In about 33 cases, the software security firm identified, 25 cases were attributed to the Qilin ransomware group, and 24 of the compromised entities were within the financial industry. 

“This operation combined the capabilities of a major Ransomware-as-a-Service (RaaS) group, Qilin, with potential involvement from North Korean state-affiliated actors (Moonstone Sleet), leveraging Managed Service Provider (MSP) compromise as the initial access vector,” the report read.

Russian and North Korean hackers steal 2 TB of data from South Korean banksVictims of ransomware in Korea. Source: Bitdefender

Qilin is one of the most active ransomware groups this year, operating under a Ransomware-as-a-Service model and claiming more than 180 victims in October alone. According to threat intelligence from NCC Group, the operation is responsible for 29% of all ransomware attacks globally.

Although the group’s name comes from a Chinese mythological creature, Bitdefender believes Qilin has Russian roots. Its investigation found one of its founding members “BianLian” communicates in Russian and English and is highly active on Russian-speaking cybercrime forums. 

The group also avoids attacking organizations in the Commonwealth of Independent States, a common rule among ransomware operations based in Russia.

Qilin recruits hackers to carry out its attacks while the core operators take a share of the illicit profits. The group also boasts of having “an in-house team of journalists” to help affiliates craft extortion messages and posts for its data leak platform.

According to Bitdefender’s analysis on the Korean Leaks campaign, the hackers posed as “activists” and “patriots” by using political language to produce propaganda-style messages, and targeted the entire country’s financial industry. 

In one case from August 20 involving a construction company, the attackers warned that the stolen data had “military intelligence value.” The message claimed that plans and drawings for hundreds of completed projects, including bridges and liquefied natural gas tanks, were now publicly accessible. 

“A report on what was found in these documents is already being prepared for Comrade Kim Jong-un,” one of the leaked discussions in Qilin forums read, insinuating that hackers were sharing info with North Korea’s group leadership.

Qilin steals data totaling 2TB in three waves

The Korean Leaks operation, according to Bitdefender, unfolded in three waves that resulted in the theft of more than 1 million files and 2TB of data from 28 known victims. Posts linked to four additional entities were later removed from the data leak site, which could have been as a result of ransom payments or internal decisions by the operators.

The first wave was published on September 14 and included 10 victims from the financial management sector. The second wave followed between September 17 and September 19, adding nine more cases, while the third was released between September 28 and October 4, targeting another nine organizations. 

“We have data on dozens of companies. The Korean Leak is a reason to withdraw money from the country’s stock market, because we have a volume of data whose publication will definitely deal a serious blow to the entire Korean market. And we will definitely do it,” read one threat from the hackers during the second wave.

Bitdefender said the attackers framed the campaign as an effort to expose corruption, including threats to release documents that could be “evidence of stock market manipulation” and names of “well-known politicians and businessmen in Korea.”

On September 23, the Korean news publication JoongAng Daily reported that more than 20 asset management companies had been infected with ransomware after the breach of a service provider called GJTec.

Get $50 free to trade crypto when you sign up to Bybit now

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

The Economics of Self-Isolation: A Game-Theoretic Analysis of Contagion in a Free Economy

The Economics of Self-Isolation: A Game-Theoretic Analysis of Contagion in a Free Economy

Exploring how the costs of a pandemic can lead to a self-enforcing lockdown in a networked economy, analyzing the resulting changes in network structure and the existence of stable equilibria.
Share
Hackernoon2025/09/17 23:00
Trump is running out of time — and Republicans ready to abandon him

Trump is running out of time — and Republicans ready to abandon him

When President Donald Trump was reelected in 2024, he rode in on a largely populist message that promised to lower prices, reduce inflation, cut taxes, and improve
Share
Alternet2026/03/23 22:02
One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02