At a Glance
- Malware Family: KRSID ransomware, Quasar RAT (historical).
- Threat Actor: Suspected investment fraud groups (Telegram: @bratteam88).
- Targets or Victims: Individuals using unauthorized private Home Trading Systems (HTS).
- Delivery Vector: Malicious software updates via the UBP Asset application.
- Key Capabilities: Drive encryption (AES-256 / RSA-2048), specific file targeting, logging.
- Source: AhnLab SEcurity intelligence Center (ASEC).
Executive Summary
Cybercriminals are distributing the new KRSID ransomware through a counterfeit investment application called UBP Asset. The attackers lure victims via social media into downloading this private HTS malware. Once installed, the trading software downloads a malicious update that encrypts user files and demands a cryptocurrency ransom.
Delivery Tactics and Social Engineering
Unlicensed financial firms often deceive users using online advertisements and text messages. These messages lure victims into group chat rooms on platforms like KakaoTalk and Telegram. The administrators in these groups promote commission-free trading and low-margin requirements. They persuade recruited users to install a private Home Trading System (HTS).
Recently, a Korean law firm blog warned about a fraudulent site impersonating the Swiss bank Union Bancaire Privee. This group distributes the UBP Asset software, which acts as private HTS malware. Previously, these fraud groups just stole deposited funds under the guise of trading fees. In older campaigns from 2023 and 2024, an unauthorized platform named HPlus distributed the Quasar RAT. Now, attackers are deploying the KRSID ransomware to extort additional payments from victims.
The Infection Chain
The infection sequence begins when a victim installs the UBP Asset application. The software typically installs in a root directory folder named “UBP-Asset”. When the user clicks the desktop shortcut, the system runs an executable named “UBPUpdater.exe”.
This updater launches a secondary script file named “UBPPatch.psh”. This script connects to an external update server and downloads a configuration file called “Update.lst”. Based on AhnLab security logs, this configuration file directs the system to download the KRSID ransomware. The system saves the ransomware as a file named “HTSPnew.exe”.
Furthermore, the attackers modified a core library file named “UBP.dll”. According to the report, “the threat actor uploaded the ransomware to the HTS server, modified the configuration file, and appears to have also added functionality to ‘UBP.dll’ to execute the ransomware.”
Encryption Behavior and Ransom Demands
The KRSID ransomware is written in the Rust programming language. Based on the ransom note contents, researchers presume artificial intelligence tools helped create the malware. When executed, the malware encrypts the entire drive using AES-256 and RSA-2048 algorithms.
It targets specific file extensions, including source code files, documents, databases, and images. The malware actively excludes critical system folders like Windows, ProgramData, and Recovery to keep the machine operational. Interestingly, this malware lacks a feature to delete volume shadow copies.
The ransomware drops a note named “README_KRSID.txt” written in Korean. The note instructs the victim to contact the Telegram account “@bratteam88” to pay the ransom in Bitcoin.
Defense and Detection Guidance
Recovering encrypted files or stolen investment funds remains highly unlikely even if victims pay the ransom. Users must avoid installing private trading systems shared in chat rooms or text messages.
The Financial Supervisory Service states, “Legitimate financial institutions do not distribute private HTS software through messaging apps or similar channels.” Investors should only download software directly from the official websites of regulated financial institutions. Always keep security software and operating systems updated to block known threats. You can review the full AhnLab SEcurity intelligence Center (ASEC) analysis for additional technical indicators and threat updates.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!