Summary: 2025/04/19 13:20

First reported date: 2008/06/10
Inquiry period : 2025/04/18 13:20 ~ 2025/04/19 13:20 (1 days), 16 search results

지난 7일 기간대비 -56% 낮은 트렌드를 보이고 있습니다.
지난 7일 기간대비 상승한 Top5 연관 키워드는
attack Malware Group DarkWeb Akira 입니다.
악성코드 유형 Lumma Sodinokibi Vidar Raccoon RedLine 도 새롭게 확인됩니다.
기관 및 기업 대만 안랩 도 새롭게 확인됩니다.
기타 Kali Browser vietnamcyberattack HIPAA Food 등 신규 키워드도 확인됩니다.

 * 최근 뉴스기사 Top3:
    ㆍ 2025/04/19 HHS fines Guam hospital over ransomware attack, HIPAA violations
    ㆍ 2025/04/19 Data breach confirmed by Ahold Delhaize after INC ransomware claims
    ㆍ 2025/04/19 Paradies Shops to settle ransomware-related breach for $6.9M


참고로 동일한 그룹의 악성코드 타입은 WannaCry Sodinokibi Phobos 등 78개 종이 확인됩니다.

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1Ransomware 16 ▼ -9 (-56%)
2attack 7 ▲ 2 (29%)
3Alert 7 ▼ -2 (-29%)
4Victim 7 ▼ -3 (-43%)
5Malware 6 ▲ 1 (17%)
6Group 4 ▲ 1 (25%)
7DarkWeb 4 ▲ 1 (25%)
8Akira 3 ▲ 1 (33%)
9Report 3 ▼ -2 (-67%)
10MWNEWS 2 - 0 (0%)
11Interlock 2 ▲ 1 (50%)
12gang 2 ▲ 1 (50%)
13ClickFix 2 ▲ 2 (100%)
14Operation 2 ▲ 1 (50%)
15Recorded Future 2 ▲ 2 (100%)
16United States 2 ▼ -1 (-50%)
17Cryptocurrency 2 ▲ 2 (100%)
18Kali 1 ▲ new
19Stealer 1 ▲ 1 (100%)
20Google 1 ▲ 1 (100%)
21Update 1 ▼ -1 (-100%)
22Criminal 1 - 0 (0%)
23Exploit 1 ▼ -1 (-100%)
24GameoverP2P 1 ▲ 1 (100%)
25Browser 1 ▲ new
26Lumma 1 ▲ new
27Telegram 1 ▲ 1 (100%)
28c&c 1 ▲ 1 (100%)
29VPN 1 ▲ 1 (100%)
30vietnamcyberattack 1 ▲ new
31Takedown 1 ▲ 1 (100%)
32breach 1 ▲ 1 (100%)
33HIPAA 1 ▲ new
34Food 1 ▲ new
35INC 1 - 0 (0%)
36Delhaize 1 ▲ new
37Ahold 1 ▲ 1 (100%)
38North 1 ▲ new
39ransomwarerelated 1 ▲ new
40Email 1 - 0 (0%)
41Shops 1 ▲ new
42Sodinokibi 1 ▲ new
43Russia 1 - 0 (0%)
44target 1 ▼ -2 (-200%)
45Software 1 - 0 (0%)
46RCE 1 ▼ -1 (-100%)
47intelligence 1 - 0 (0%)
48Campaign 1 ▼ -1 (-100%)
49Could 1 ▲ new
50Phishing 1 - 0 (0%)
51Taiwan 1 - 0 (0%)
52CMC 1 ▲ new
53onset 1 ▲ new
54Vietnams 1 ▲ new
55Global 1 ▲ 1 (100%)
56Media 1 ▲ new
57Hubbard 1 ▲ new
58Mcllwainamp 1 ▲ new
59Qilin 1 - 0 (0%)
60LYNX 1 - 0 (0%)
61DH 1 ▲ new
62Smith 1 ▲ new
63RSA Conference 1 ▲ 1 (100%)
64Japan 1 ▲ 1 (100%)
65AhnLab 1 ▲ 1 (100%)
66Kaspersky 1 - 0 (0%)
67Dark 1 - 0 (0%)
68Vidar 1 ▲ new
69Raccoon 1 ▲ new
70RedLine 1 ▲ new
71Survive 1 ▲ new
72April 1 ▲ 1 (100%)
73Reading 1 ▲ 1 (100%)
74Agency 1 ▲ new
75Education 1 - 0 (0%)
76Title 1 ▲ new
77Indipendent 1 ▲ new
78솔루션 1 ▲ new
79대만 1 ▲ new
80안랩 1 ▲ new
81conference 1 ▲ 1 (100%)
82HHS 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
Ransomware
16 (64%)
Akira
3 (12%)
GameoverP2P
1 (4%)
Lumma
1 (4%)
Sodinokibi
1 (4%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


No data.

Attack technique
Technique

This is an attack technique that is becoming an issue.


Keyword Average Label
ClickFix
2 (28.6%)
Stealer
1 (14.3%)
Exploit
1 (14.3%)
RCE
1 (14.3%)
Campaign
1 (14.3%)
Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
Recorded Future
2 (16.7%)
United States
2 (16.7%)
Google
1 (8.3%)
Russia
1 (8.3%)
Taiwan
1 (8.3%)
Malware Family
Top 5

A malware family is a group of applications with similar attack techniques.
In this trend, it is classified into Ransomware, Stealer, RAT or Backdoor, Loader, Botnet, Cryptocurrency Miner.

Threat info
Last 5

SNS

(Total : 11)
  Total keyword

Ransomware Victim DarkWeb attack Akira ClickFix Report Cryptocurrency Malware

No Title Date
1Cyber_OSINT @Cyber_O51NT
On April 12, 2025, CMC Group engineers experienced the onset of Vietnam's most notable ransomware attack, as network logs revealed an unfamiliar admin account probing hidden developer subnets. #CyberSecurity #VietnamCyberAttack https://t.co/J9g2I9tBAk
2025.04.18
2FalconFeeds.io @FalconFeedsio
????Ransomware Alert: Akira ransomware group has added 2 new victims to their dark web portal. - Agencia Browne y Espinoza ???????? An accounting company based in Chile. NB : The group claims to have obtained 37 GB of organization's data. - Heinz Hammer Vertragswerkstatt GmbH ???????? A https:
2025.04.18
3FalconFeeds.io @FalconFeedsio
???? Ransomware Alert: D.H. Smith Company Inc (https://t.co/npPKtnvJjq), a licensed and bonded contractor specializing in lathing and plastering services, based in USA, has fallen victim to LYNX Ransomware ???? Key Details: ????Threat Actor : LYNX ????Published date : 18-04-2025 ???? https://t.c
2025.04.18
4FalconFeeds.io @FalconFeedsio
???? Ransomware Alert: Hubbard, Mcllwain,& Brakefield, P.C (https://t.co/OL2JeOKEex), a Tuscaloosa, Alabama-based law firm, has fallen victim to Akira ransomware. ???? Key Details: ????Threat Actor : Akira ????Published date : 18-04-2025 ⚠ Data Size : 4 GB https://t.co/J8jfeSmJId
2025.04.18
5BleepingComputer @BleepinComputer
Interlock ransomware gang pushes fake IT tools in ClickFix attacks - @billtoulas https://t.co/I1Na1PgWU6 https://t.co/I1Na1PgWU6
2025.04.18

Additional information

No Request Hash(md5) Report No Date
1 hello.exe
Ransomware Malicious Library .NET EXE PE32 PE File
69d1c11ae24884ea55ab39787853ad0c553312024.11.13
Level Description
danger File has been identified by 58 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Collects information to fingerprint the system (MachineGuid
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
No data
No URL CC ASN Co Reporter Date
1https://hilarious-trifle-d9182e.netlify.app/lootsubmit.ps1
fog Ransomware
SG SGAMAZON-02JAMESWT_WT2025.04.04
2https://hilarious-trifle-d9182e.netlify.app/cwiper.exe
fog Ransomware
SG SGAMAZON-02JAMESWT_WT2025.04.04
3https://hilarious-trifle-d9182e.netlify.app/Pay
fog Ransomware
SG SGAMAZON-02JAMESWT_WT2025.04.04
4https://hilarious-trifle-d9182e.netlify.app/stage1.ps1
fog Ransomware
SG SGAMAZON-02JAMESWT_WT2025.04.04
5https://hilarious-trifle-d9182e.netlify.app/Pay%20Adjustment.zip
fog Ransomware
SG SGAMAZON-02JAMESWT_WT2025.04.04
View only the last 5
Beta Service, If you select keyword, you can check detailed information.