VCD Ransomware is a newly observed ransomware family identified in a malware campaign targeting South Korean users. It encrypts files and appends the .VCD extension to affected files. According to S2W, it was delivered as part of a broader infection chain that began with a malicious LNK file embedded in a RAR archive, themed as a postal-code update notice. Execution of the LNK dropped an AutoIt loader, which retrieved additional payloads from an external server, including VCD Ransomware, the LightPeek and FadeStealer stealers, and the NubSpy and CHILLYCHINO backdoors. S2W attributed the campaign to ChinopuNK, a subgroup of the North Korean state-sponsored ScarCruft (APT37) threat cluster. The ransomware deployment was described as a notable deviation from ScarCruft’s historically espionage-focused operations and may indicate either financially motivated activity or an expansion into disruptive or extortion-oriented tactics. High-confidence associated context includes targeting of South Korean users and use alongside PubNub-enabled ScarCruft tooling in the same campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VCD Ransomware : A newly observed ransomware that appends the .VCD extension to encrypted files upon infection.
VCD Ransomware : A newly observed ransomware that appends the .VCD extension to encrypted files upon infection.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly observed ransomware that encrypts files and appends the .VCD extension.
VCD Ransomware is a ransomware payload deployed by North Korean threat actors, encrypting files and demanding payment for decryption.
Ransomware deployed by the North Korean ScarCruft APT group (specifically ChinopuNK subgroup) in attacks that previously focused on espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.