What has been described as a sophisticated supply chain operation that resulted in the deployment of Qilin ransomware targeted South Korea’s financial industry.
According to a report shared with The Hacker News by Bitdefender, this operation used Managed Service Provider (MSP) compromise as the initial access vector, combining the capabilities of a significant Ransomware-as-a-Service (RaaS) group, Qilin, with possible involvement from North Korean state-affiliated actors (Moonstone Sleet).
The RaaS team demonstrated “explosive growth” in October 2025, claiming over 180 victims, making Qilin one of the most active ransomware operations this year. According to data from NCC Group, the group is accountable for 29% of all ransomware outbreaks.
In September 2025, South Korea became the second most affected country after the United States with 25 cases of ransomware read more about Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
