Quick Summary
AllegedExecutive Summary
MetaEncryptor has targeted HyVision System. Inc, a South Korean developer of video analytics and intelligent security systems, adding them to its list of victims on September 21, 2026. The listing was identified by SOCRadar’s Dark Web Monitoring. HyVision System. Inc serves enterprise and government clients, making its operations a potential target for ransomware operations due to the sensitive nature of the data it handles. In the preceding 60 days, MetaEncryptor has claimed approximately 20 other victims, primarily within the Manufacturing, Healthcare, and Technology sectors. The ransomware group has frequently targeted organizations in the US, South Korea, and Japan. HyVision System. Inc aligns directly with MetaEncryptor’s focus on South Korean technology companies, similar to its previous victim SFA Engineering Corporation.
Technical Analysis
SOCRadar’s investigation into the domain en.hyvision[.]co[.]kr, associated with HyVision System. Inc, returned no stealer-log records. This specific subdomain, en.hyvision[.]co[.]kr, likely handles limited corporate traffic due to its English designation. It is common for South Korean corporate environments to utilize the base domain (hyvision[.]co[.]kr) or employ internal naming conventions that would not be captured by a query targeting only a single subdomain. Therefore, a null result from this specific query holds less definitive information than it might for a target in a region with more standardized domain usage, such as the United States. The absence of immediate telemetry does not confirm that HyVision System. Inc is unaffected by credential harvesting. Korean corporate networks often use the primary domain, hyvision[.]co[.]kr, or distinct internal naming schemes for subdomains that were not included in the initial query. Consequently, the lack of records on the English subdomain should not be interpreted as definitive proof of security. Continued monitoring across hyvision[.]co[.]kr, as well as any known VPN or identity provider endpoints associated with the company, is recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.