securityonline.info 23 Sept 2026, 06:15 UTC

Fake Trading App Delivers KRSID Ransomware to South Korean Victims

Fake Trading App Delivers KRSID Ransomware to South Korean Victims

CYBERCRIMINALS are distributing KRSID ransomware through UBP Asset, a counterfeit investment application presented as a private Home Trading System (HTS). According to analysis from AhnLab’s SEcurity intelligence Center (ASEC), victims are recruited through social media, text messages and KakaoTalk or Telegram groups promoting supposedly commission-free trading. The campaign reportedly follows earlier fraud operations in which an unauthorised HTS called HPlus distributed Quasar RAT. Victims may also lose deposited funds to the underlying investment scam.

The infection begins when UBP Asset is installed in a folder named “UBP-Asset” and its shortcut runs “UBPUpdater.exe”. That updater launches “UBPPatch.psh”, which contacts an update server and retrieves “Update.lst”. AhnLab’s logs indicate that the configuration directs the system to download KRSID as “HTSPnew.exe”. Attackers also modified “UBP.dll”, apparently adding functionality to execute the ransomware.

Written in Rust, KRSID encrypts targeted source code, document, database and image files using AES-256 and RSA-2048, while excluding folders including Windows, ProgramData and Recovery. It does not delete volume shadow copies. The Korean ransom note, “README_KRSID.txt”, tells victims to contact Telegram account “@bratteam88” and pay in Bitcoin. The report says recovery of encrypted files or lost investment funds is unlikely even after payment.

South Korea’s Financial Supervisory Service advises that legitimate financial institutions do not distribute private HTS software through messaging apps; users should obtain trading software only from regulated institutions’ official websites.

View full article

Article by CyberSIXT