VHD ransomware is a ransomware family first observed in 2020 and attributed with high confidence to North Korean operators, specifically activity associated with Lazarus-linked financial intrusion clusters such as APT38. It has been reported as distributed through the MATA framework and has been observed in incidents alongside known Lazarus tooling, including campaigns targeting businesses in France and Asia and broader activity focused on the APAC region.
The malware is notable for targeted rather than indiscriminate deployment. Reporting has characterized VHD and closely related families as part of narrowly scoped revenue-generation operations rather than conventional large-scale criminal ransomware campaigns. Observed ransom demands and payments were comparatively small, and the activity has been assessed as aligned with DPRK state-backed financial objectives. In at least one broader DPRK-linked intrusion context, ransomware was reportedly used as a distraction during financially motivated operations.
VHD ransomware has also drawn attention for its self-replication behavior. Code and artifact analysis has linked it to several other small ransomware families, including BEAF, PXJ, ZZZZ, and CHiCHi, with especially strong similarity between BEAF and ZZZZ. These overlaps, together with operational context and delivery through MATA, support assessment that VHD belongs to a cluster of related DPRK-associated ransomware tooling.
The family is associated with Lazarus Group operations and fits within North Korea’s broader pattern of combining espionage, disruptive activity, and revenue-generating cyber operations. Its known use against business targets and its linkage to financially motivated DPRK campaigns make it significant less as a mass-extortion threat than as a specialized ransomware capability embedded in state-directed intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In May, researchers at cybersecurity firm Trellix tied the recently emerged VHD ransomware to the North Korean APT.
in March 2020, a new malware family surfaced called ‘VHD ransomware’... Many in the industry attributed the VHD ransomware to DPRK hackers. It was distributed using the MATA framework
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The ransomware itself is nothing special: it’s written in C++ and crawls all connected disks to encrypt files... Files are encrypted with a combination of AES-256 in ECB mode and RSA-2048.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family first seen in March 2020 and attributed in the article to DPRK-linked operators. It was reportedly distributed via the MATA framework and used in targeted attacks, particularly in the APAC region, with relatively small ransom payments observed.
A recently emerged ransomware family that the article mentions as being tied to Lazarus in separate reporting.
VHD is a ransomware family notable for its self-replication and use in targeted attacks, attributed to the Lazarus group.
Named ransomware referenced in the context of DPRK expanded criminal operations targeting cryptocurrency-related entities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.