South Korea’s financial sector was hit by a coordinated Russia–North Korea supply chain attack using Qilin ransomware, with 2 TB of sensitive banking data stolen. South Korea’s financial sector suffered a coordinated supply chain attack attributed to Russian and North…South Korea’s financial sector was hit by a coordinated Russia–North Korea supply chain attack using Qilin ransomware, with 2 TB of sensitive banking data stolen. South Korea’s financial sector suffered a coordinated supply chain attack attributed to Russian and North…

South Korea banks hit by Russia–North Korea ransomware alliance

South Korea’s financial sector was hit by a coordinated Russia–North Korea supply chain attack using Qilin ransomware, with 2 TB of sensitive banking data stolen.

Summary
  • Bitdefender’s October Threat Debrief details how threat actors breached a third‑party vendor to infiltrate multiple South Korean financial institutions.​
  • Attackers deployed Qilin ransomware across compromised networks after initial access, exfiltrating roughly 2 terabytes of data from targeted banks.​
  • The joint involvement of Russian and North Korean state‑linked actors marks an escalation in supply chain tactics against critical financial infrastructure.

South Korea’s financial sector suffered a coordinated supply chain attack attributed to Russian and North Korean threat actors, resulting in the deployment of Qilin ransomware and the theft of sensitive data, according to cybersecurity firm Bitdefender.

The attack, detailed in Bitdefender’s Threat Debrief October report, led to the compromise of multiple South Korean banking institutions. The firm stated it began investigating the campaign after identifying suspicious activity linked to the threat actors.

Analysts warn of more coordinated ransomware attacks by Russian and North Korean hackers

The coordinated operation involved threat actors from both Russia and North Korea working in tandem to breach the financial institutions’ systems, Bitdefender reported. The attackers successfully exfiltrated approximately 2 terabytes of data from the targeted banks.

The supply chain attack method allowed the threat actors to gain access to multiple organizations through a compromised third-party vendor or service provider, according to the report. Following initial access, the attackers deployed Qilin ransomware across the compromised networks.

Bitdefender confirmed the findings in its monthly threat intelligence report covering October activity. The cybersecurity firm did not immediately disclose the specific identities of the affected South Korean financial institutions or the timeline of the breach.

Supply chain attacks have become an increasingly common tactic among state-sponsored threat actors, allowing attackers to compromise multiple targets through a single point of entry. The involvement of both Russian and North Korean actors in a coordinated operation represents a notable development in the cybersecurity threat landscape.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Vitalik Buterin Reaffirms Original 2014 Ethereum Vision With Modern Web3 Technology Stack

Vitalik Buterin Reaffirms Original 2014 Ethereum Vision With Modern Web3 Technology Stack

TLDR: Ethereum proof-of-stake transition and ZK-EVM scaling solutions effectively realize the 2014 sharding vision. Waku evolved from Whisper to power decentralized
Share
Blockonomi2026/01/14 17:17
CME Group to Launch Solana and XRP Futures Options

CME Group to Launch Solana and XRP Futures Options

The post CME Group to Launch Solana and XRP Futures Options appeared on BitcoinEthereumNews.com. An announcement was made by CME Group, the largest derivatives exchanger worldwide, revealed that it would introduce options for Solana and XRP futures. It is the latest addition to CME crypto derivatives as institutions and retail investors increase their demand for Solana and XRP. CME Expands Crypto Offerings With Solana and XRP Options Launch According to a press release, the launch is scheduled for October 13, 2025, pending regulatory approval. The new products will allow traders to access options on Solana, Micro Solana, XRP, and Micro XRP futures. Expiries will be offered on business days on a monthly, and quarterly basis to provide more flexibility to market players. CME Group said the contracts are designed to meet demand from institutions, hedge funds, and active retail traders. According to Giovanni Vicioso, the launch reflects high liquidity in Solana and XRP futures. Vicioso is the Global Head of Cryptocurrency Products for the CME Group. He noted that the new contracts will provide additional tools for risk management and exposure strategies. Recently, CME XRP futures registered record open interest amid ETF approval optimism, reinforcing confidence in contract demand. Cumberland, one of the leading liquidity providers, welcomed the development and said it highlights the shift beyond Bitcoin and Ethereum. FalconX, another trading firm, added that rising digital asset treasuries are increasing the need for hedging tools on alternative tokens like Solana and XRP. High Record Trading Volumes Demand Solana and XRP Futures Solana futures and XRP continue to gain popularity since their launch earlier this year. According to CME official records, many have bought and sold more than 540,000 Solana futures contracts since March. A value that amounts to over $22 billion dollars. Solana contracts hit a record 9,000 contracts in August, worth $437 million. Open interest also set a record at 12,500 contracts.…
Share
BitcoinEthereumNews2025/09/18 01:39
U.S. politician makes super suspicious war stock trade

U.S. politician makes super suspicious war stock trade

The post U.S. politician makes super suspicious war stock trade appeared on BitcoinEthereumNews.com. Representative Gilbert Cisneros of California drew much attention
Share
BitcoinEthereumNews2026/01/14 17:27