South Korea’s Financial Sector Targeted in Sophisticated Ransomware Campaign Linked to Qilin Group
South Korea's financial industry faced an unprecedented wave of ransomware attacks in September, with security firm Bitdefender documenting 25 incidents—a dramatic spike from the typical monthly average of two cases. The Qilin ransomware group, operating under a RaaS model, accounted for 24 of these breaches, predominantly targeting financial institutions.
The campaign's sophistication suggests potential collaboration between cybercriminal groups and state-affiliated actors. Qilin has emerged as one of 2024's most active threats, claiming over 180 victims globally in October alone. This represents 29% of all ransomware attacks tracked by NCC Group during the period.
Managed Service Provider compromises served as the primary attack vector, highlighting systemic vulnerabilities in third-party IT infrastructure. The scale and focus on financial targets mirror patterns seen in North Korean-linked cyber operations, though attribution remains unconfirmed.