logo

MAFIA ransomware targeting users in Korea

ID: 4b32523a-91d5-5e03-b250-b7602bbd84b1

STIX ID: report--4b32523a-91d5-5e03-b250-b7602bbd84b1

Feed Name: Blaze's Security Blog

Threat Score
73/100

Date Published: 2018-08-12

Date Updated: 2026-04-19

Author: Bart

...
...

This report analyzes the MAFIA ransomware targeting Korean users, detailing its use of OpenSSL-based AES-256-CBC encryption that appends the .MAFIA extension, attempts to stop the South Korean AppCheck anti-ransomware service, and creation of an HTML ransom note. It communicates with C2 via Tor proxies (onion.pet/onion.plus), transmits IV and key values in HTTP GET parameters, and provides multiple sample hashes and domains as IOCs, indicating an active yet somewhat localized criminal ransomware threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.