Ransomware Group intelligence
ULose
ActiveTrack ULose with 9 published victims and 1 known leak locations in a single intelligence view.
Overview
ULose is tracked by Breach House as a ransomware group with 9 published victims.
Korea, Republic of is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 4h ago | egm34gsyx65wb6jyqds4esvkskl34barx4robuebjhqpc4dfeavg7fyd.onion |
Top Activity Sectors (3)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue ULose, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: ULose executes malicious payloads through PowerShell scripts to deploy ransomware binaries across targeted Engineering networks.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: ULose disables security tools by terminating antivirus processes and modifying Windows Defender policies to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: ULose encrypts victim files with encoded payloads stored in temporary directories to evade static detection scanners.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: ULose deletes Volume Shadow Copies and backup directories via vssadmin and built-in Windows commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: ULose uses file and directory discovery via PowerShell to enumerate critical assets across Finance and Healthcare systems before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1614.001 System Language Discovery Discovery
What they do: ULose performs system language discovery to tailor encryption patterns for localized KR manufacturing and healthcare environments.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1560.001 Archive via Utility Collection
What they do: ULose archives stolen data from Legal and Insurance client records using built-in utility commands prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: ULose encrypts victim data using custom symmetric encryption routines targeting Finance and Insurance databases before demanding ransom.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: ULose stops critical Windows services like SQL Server and email systems via net stop commands to maximize operational disruption.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: ULose inhibits system recovery by corrupting restore points and disabling backup service processes on compromised KR infrastructure.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (9)
Search, filter and paginate the victim timeline for ULose. Showing 1–9 of 9.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | NRCapital id30676 View details | Korea, Republic of | Finance / Legal / Insurance | — | |
|
NRCapital.co.kr is a financial services company based in South Korea, operating in the finance, legal, and insurance sector. The company provides various financial solutions and services to its clients. NRCapital.co.kr was listed as a ransomware victim associated with ULose |
|||||
| Ransomware | HanDok id30677 View details | Korea, Republic of | Healthcare / Pharma | — | |
|
Handok is a South Korean company operating in the healthcare and pharmaceutical sector, offering various products and services. Based in Korea, the company is involved in the development and distribution of pharmaceuticals and other healthcare-related offerings. Handok was listed as a ransomware victim associated with ULose |
|||||
| Ransomware | KyungRok id30678 View details | Korea, Republic of | Manufacturing / Engineering | — | |
|
Kyungrok.com is a South Korean company operating in the manufacturing and engineering sector, providing various offerings to its clients. The company is based in Korea and serves the local market with its products and services. Kyungrok.com was listed as a ransomware victim associated with ULose. |
|||||
| Ransomware | HIZE Aero id30679 View details | Korea, Republic of | Manufacturing / Engineering | — | |
|
Hizeaero.com operates in the manufacturing and engineering sector, based in South Korea, providing various products and services. The company's offerings cater to the needs of its clients in the region. Hizeaero.com was listed as a ransomware victim associated with ULose |
|||||
| Ransomware | MSICapital id30680 View details | Korea, Republic of | Finance / Legal / Insurance | — | |
|
Money-store.co.kr is a financial services provider based in South Korea, offering various financial products and services to its customers. As a part of the finance sector in KR, the company operates within the legal and insurance industries. Money-store.co.kr was listed as a ransomware victim associated with ULose. |
|||||
| Ransomware | NRCapital id30676 View details | Korea, Republic of | Finance / Legal / Insurance | — | |
|
We have all data of nrcapital company. 1TB. country: South Korea status: private |
|||||
| Ransomware | HanDok id30677 View details | Korea, Republic of | Healthcare / Pharma | — | |
|
We have all customer`s data of HanDok country: South Korea status: public |
|||||
| Ransomware | KyungRok id30678 View details | Korea, Republic of | Manufacturing / Engineering | — | |
|
We have all customer`s data of KyungRok country: South Korea status: public |
|||||
| Ransomware | HIZE Aero id30679 View details | Korea, Republic of | Manufacturing / Engineering | — | |
|
We have all PDM Server`s data of HIZEAERO Company, partner Boeing. 1TB country: South Korea status: private |
|||||