PULSE NAME
Malicious documents spreading Ransomware
WHITE trainingstudent 2026-05-18 Modified: 2026-05-18
18
IOCs
MEDIUM VOLUME
Recently, the most problematic targeted attack in Korea is the Ammyy remote control backdoor being distributed to companies and the Clop ransomware installed through it. The backdoor file was created using the source of the Ammyy remote control program, which is available online, and is planted on the PC being attacked before accessing the system remotely. The malicious file that the attacker wants to finally execute on the system is the Clop ransomware.
Indicators of Compromise (4 / 18 total)
All FileHash-SHA256 URL hostname FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 8364f1e42b4467f527e875e4cf20fe8a 2026-05-18
FileHash-MD5 800db6507256cde0514990f2bf0a414a 2026-05-18
FileHash-MD5 d46778cf23d9b6d092be5f75b86700bb 2026-05-18
FileHash-MD5 57f59b1e113dffb36015af3523344ab1 2026-05-18