RA World is a financially motivated ransomware operation that has attacked organizations including South Korean companies. Its attacks involve file encryption and ransom demands, and it has been identified among ransomware groups using payloads derived from leaked Babuk or LockBit builders. RA World activity has involved PlugX, the Impacket toolkit, and NPS tunneling software, alongside exploitation of the PAN-OS vulnerability CVE-2024-0012. These tools support compromised-network access and post-exploitation activity. Its use by an espionage-linked operator does not establish that the ransomware operation itself is state-sponsored or based in China.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RA World is a ransomware group that targeted Korean companies in 2023 as part of a surge in ransomware activity in Asia.
Ransomware operation mentioned as a separate example of overlap between Chinese espionage activity and ransomware affiliate operations. No direct connection to Storm-2603 or Warlock is established.
Ransomware operation suspected (in this text) to have linkage to Chinese cyber-espionage; associated with PlugX usage, offensive tooling, and exploitation of PAN-OS.
Mentioned as a competing ransomware operation using leaked builders, contrasting with BlackLock's bespoke malware. The passage does not identify which builder RA World uses.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.