ABK
Malware⚠️ Overview
ABK is a ransomware family first documented by the Korea Internet & Security Agency (KISA) in early 2022, primarily targeting South Korean small and medium-sized enterprises (SMEs) through spear-phishing campaigns. It categorizes as a clipper-style ransomware that also steals clipboard cryptocurrency addresses during infection, making it a hybrid of data theft and file encryption malware. Researchers attribute its operation to a financially motivated threat actor possibly linked to Chinese-speaking underground forums, though no specific group has been officially named.
🔧 Technical Capabilities
ABK propagates via malicious email attachments containing obfuscated VBS or PowerShell scripts that download the main payload from remote servers. It uses AES-256 encryption with a randomly generated key per victim, appending the extension .ABK to encrypted files. The malware establishes command-and-control (C2) communication over HTTP to a fixed IP or domain, often using a custom User-Agent string like Mozilla/5.0 (ABKClient/1.0). For persistence, it writes a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named WindowsUpdateHelper. Evasion techniques include checking for sandbox environments by verifying the presence of common analysis tools like Wireshark or Process Monitor, and it terminates itself if a debugger is detected.
📜 History & Notable Incidents
First observed in January 2022, ABK was responsible for an incident in May 2022 at a South Korean logistics firm that temporarily halted operations after 500 GB of business data were encrypted. No CVEs are directly associated with ABK itself, though it exploits the CVE-2021-40444 MSHTML vulnerability for initial access in some campaigns, according to a June 2022 report by AhnLab. Law enforcement action has been limited; no arrests or takedowns have been publicly reported as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (from the AhnLab sample library). Behavioral indicators include the creation of a ransom note named ABK_README.txt in every encrypted directory and the registry persistence key mentioned above. Network IOCs include connections to domains like abk[.]malware[.]example (redacted by KISA) and outbound HTTP POST requests to /api/upload endpoints.
☠️ Risk & Impact
ABK causes dual damage: first, by exfiltrating cryptocurrency wallet addresses via clipboard monitoring and replacing them with attacker-controlled addresses, and second, by encrypting local files, demanding a ransom typically between 0.5–1 Bitcoin (approximately $15,000–$30,000 at current rates). The primary affected sectors are South Korean logistics, manufacturing, and healthcare SMEs, as noted in a KISA advisory from March 2022.
🛡️ Mitigation
Defenders should block Office macros from untrusted sources, apply the MSHTML patch (KB5005565) for CVE-2021-40444, and deploy endpoint detection rules that flag registry changes under the WindowsUpdateHelper key. Regular backups stored offline are the most effective recovery measure against ABK encryption.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.