Gwisin is a targeted ransomware family used against companies in South Korea. It is delivered as an MSI installer containing a DLL whose activation requires victim-specific execution parameters, reducing the likelihood that an MSI analyzed without the required arguments will exhibit malicious behavior. On Windows, Gwisin decrypts internal shellcode and injects it into legitimate processes to execute in memory, encrypts files, and appends an extension derived from the targeted organization’s name. It creates organization-specific ransom notes that include contact information and references to stolen data.
Gwisin supports a Safe Mode encryption mode. In this mode, it installs itself as a service, modifies boot configuration to start Safe Mode, forces a reboot, and encrypts files after restart. It can delete system event logs and remove ransomware artifacts following encryption. Intrusions associated with Gwisin have involved compromise of public-facing servers through web exploitation, followed by credential theft, internal network reconnaissance, and distribution of Windows and Linux payloads through internally hosted web services, Active Directory policy, and WMI. This distribution approach enables encryption of internal systems that do not have direct Internet connectivity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced as an example of malware detectable through MSIEXEC-delivered malicious DLL execution and Windows Installer custom actions.
Ransomware referenced as matching a detection for malicious DLL execution through Windows Installer (MSIEXEC), specifically DLLRegisterServer invocation.
Ransomware used after compromise of public-facing servers and lateral movement inside victim networks. The attacker distributes Windows and Linux payloads internally via IIS, WMI, AD policy, and other administrative mechanisms, encrypts files, appends victim-specific extensions, drops ransom notes with victim-identifying strings and portal credentials, and deletes event logs and ransomware files after encryption.
Ransomware reportedly used against companies in South Korea. It is delivered via an MSI installer containing a DLL that executes only when specific installation criteria are met, then encrypts files and renames them with an extension based on the victim company.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.