Gwisin ransomware has targeted Korean companies using MSI installers tailored to specific victims. The MSI requires execution arguments to activate its embedded DLL, limiting sandbox visibility; it decrypts shellcode, injects it into legitimate processes including certreq.exe, and encrypts files in memory. The malware can disable security products, install itself as a service, alter boot settings, and reboot hosts into Safe Mode before encryption. Encrypted files receive an extension based on the victim organization’s name, while ransom notes claim data theft and provide attacker contact details.
Defenders can improve visibility into this execution chain by monitoring non-Microsoft-signed DLL loads and correlating DLL telemetry with process, file-timing, and mounted-device metadata. High-value detections include suspicious DLL execution through msiexec, Rundll32, Regsvr32, Office applications, disk-image or archive delivery, DLL sideloading, unusual directories, removable media, and timestomping. DLL-load analytics should be paired with behavior-based shellcode and process-injection detection, malware classification, and UEBA to identify targeted ransomware activity before encryption completes.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Elastic described detection approaches using non-Microsoft-signed DLL image-load telemetry, including correlations with process, signing, device, and file-timing data. The guidance covered malicious DLL execution through Rundll32, Regsvr32, MSIEXEC, disk images, Office documents, archives, LOLBins, and DLL sideloading.
Gwisin ransomware was increasingly used against specifically targeted Korean companies. The campaign used MSI installers requiring special execution arguments, injected decrypted shellcode into legitimate Windows processes, and could reboot systems into Safe Mode to encrypt files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.