Skip to main content

Private HTS programs that spread ransomware

0
Medium
Published: 09/18/2026 (09/18/2026, 13:20:16 UTC)
Source: AlienVault OTX General

Description

Fraudulent organizations in Korea are exploiting private Home Trading System (HTS) software to distribute ransomware to victims. The unauthorized HTS program called 'UBP Asset' impersonates the legitimate Swiss financial institution Union Bancaire Privee (UBP) and has been used in investment scams since at least September 2025. Attackers lure victims through social media platforms like Telegram and KakaoTalk, convincing them to install the fraudulent HTS and deposit funds. The latest campaign involves distributing KRSID ransomware through the HTS update mechanism, which encrypts files using AES-256 and RSA-2048 algorithms. Previous campaigns used similar private HTS programs to distribute Quasar RAT. Victims not only lose their investment funds but also have their systems compromised and files encrypted for ransom demands.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 14:31:35 UTC

Technical Analysis

This threat involves fraudulent private HTS software called 'UBP Asset' used by Korean-based malicious actors to impersonate a legitimate Swiss financial institution and conduct investment scams. The attackers distribute ransomware (KRSID) via the HTS update mechanism, which encrypts files using strong cryptographic algorithms (AES-256 and RSA-2048). Prior campaigns leveraged similar HTS programs to distribute Quasar RAT, enabling system compromise. The infection vector includes social engineering through social media platforms to convince victims to install the malicious HTS software and deposit funds. The campaign results in both financial loss and system compromise with encrypted files held for ransom.

Potential Impact

Victims lose invested funds due to fraudulent investment scams and suffer system compromise through the installation of malicious HTS software. The ransomware component encrypts files with strong encryption, potentially causing significant data loss unless ransom demands are met. The presence of Quasar RAT in previous campaigns indicates potential for persistent remote access and further exploitation. Overall, the impact includes financial loss, data encryption, and system compromise.

Defensive Guidance

No official patch or remediation is available as this is a social engineering and malware distribution campaign involving fraudulent software. Organizations and individuals should avoid installing unauthorized HTS software and verify the authenticity of financial applications. Awareness campaigns to educate users about the risks of installing software from untrusted sources and the dangers of investment scams on social media platforms are recommended. Monitor for indicators of compromise such as the provided hashes and domain 'phf-ubp.com' to detect potential infections.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://asec.ahnlab.com/en/95469/"]
Pulse Id
6aad3a912f6a15e61e12e20f

Indicators of Compromise

Hash

ValueDescriptionCopy
hash6d2cd65dbd0df30404b08ff007359e54
hasha9cce44c4d42b07f114dd2b340f0046a
hashf86b2ece324cfd36e832a3b48cc3719b
hash5b26921e4f7b4dac140297b0401cf0f56e1d4852
hashed7f260d4163d31add855a19652fa7c0adcc2eba4e0281f872eb7f43e0769814

Domain

ValueDescriptionCopy
domainphf-ubp.com

Threat ID: 6aad47c755bf5e2cf51b60c1

Added to database: 09/18/2026, 14:16:39 UTC

Last enriched: 09/18/2026, 14:31:35 UTC

Last updated: 09/19/2026, 03:06:54 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses