Private HTS programs that spread ransomware
Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands.
AI Analysis
Technical Summary
This threat involves fraudulent private HTS software called 'UBP Asset' used by Korean-based malicious actors to impersonate a legitimate Swiss financial institution and conduct investment scams. The attackers distribute ransomware (KRSID) via the HTS update mechanism, which encrypts files using strong cryptographic algorithms (AES-256 and RSA-2048). Prior campaigns leveraged similar HTS programs to distribute Quasar RAT, enabling system compromise. The infection vector includes social engineering through social media platforms to convince victims to install the malicious HTS software and deposit funds. The campaign results in both financial loss and system compromise with encrypted files held for ransom.
Potential Impact
Victims lose invested funds due to fraudulent investment scams and suffer system compromise through the installation of malicious HTS software. The ransomware component encrypts files with strong encryption, potentially causing significant data loss unless ransom demands are met. The presence of Quasar RAT in previous campaigns indicates potential for persistent remote access and further exploitation. Overall, the impact includes financial loss, data encryption, and system compromise.
Mitigation Recommendations
No official patch or remediation is available as this is a social engineering and malware distribution campaign involving fraudulent software. Organizations and individuals should avoid installing unauthorized HTS software and verify the authenticity of financial applications. Awareness campaigns to educate users about the risks of installing software from untrusted sources and the dangers of investment scams on social media platforms are recommended. Monitor for indicators of compromise such as the provided hashes and domain 'phf-ubp.com' to detect potential infections.
Indicators of Compromise
- hash: 6d2cd65dbd0df30404b08ff007359e54
- hash: a9cce44c4d42b07f114dd2b340f0046a
- hash: f86b2ece324cfd36e832a3b48cc3719b
- domain: phf-ubp.com
- hash: 5b26921e4f7b4dac140297b0401cf0f56e1d4852
- hash: ed7f260d4163d31add855a19652fa7c0adcc2eba4e0281f872eb7f43e0769814
Private HTS programs that spread ransomware
Description
Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves fraudulent private HTS software called 'UBP Asset' used by Korean-based malicious actors to impersonate a legitimate Swiss financial institution and conduct investment scams. The attackers distribute ransomware (KRSID) via the HTS update mechanism, which encrypts files using strong cryptographic algorithms (AES-256 and RSA-2048). Prior campaigns leveraged similar HTS programs to distribute Quasar RAT, enabling system compromise. The infection vector includes social engineering through social media platforms to convince victims to install the malicious HTS software and deposit funds. The campaign results in both financial loss and system compromise with encrypted files held for ransom.
Potential Impact
Victims lose invested funds due to fraudulent investment scams and suffer system compromise through the installation of malicious HTS software. The ransomware component encrypts files with strong encryption, potentially causing significant data loss unless ransom demands are met. The presence of Quasar RAT in previous campaigns indicates potential for persistent remote access and further exploitation. Overall, the impact includes financial loss, data encryption, and system compromise.
Defensive Guidance
No official patch or remediation is available as this is a social engineering and malware distribution campaign involving fraudulent software. Organizations and individuals should avoid installing unauthorized HTS software and verify the authenticity of financial applications. Awareness campaigns to educate users about the risks of installing software from untrusted sources and the dangers of investment scams on social media platforms are recommended. Monitor for indicators of compromise such as the provided hashes and domain 'phf-ubp.com' to detect potential infections.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://asec.ahnlab.com/en/95469/"]
- Pulse Id
- 6aad3a912f6a15e61e12e20f
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash6d2cd65dbd0df30404b08ff007359e54 | — | |
hasha9cce44c4d42b07f114dd2b340f0046a | — | |
hashf86b2ece324cfd36e832a3b48cc3719b | — | |
hash5b26921e4f7b4dac140297b0401cf0f56e1d4852 | — | |
hashed7f260d4163d31add855a19652fa7c0adcc2eba4e0281f872eb7f43e0769814 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainphf-ubp.com | — |
Threat ID: 6aad47c755bf5e2cf51b60c1
Added to database: 09/18/2026, 14:16:39 UTC
Last enriched: 09/18/2026, 14:31:35 UTC
Last updated: 09/19/2026, 03:06:54 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.