Quick Summary
AllegedExecutive Summary
worldtube, a technology company based in South Korea, was listed as a victim on the Gunra ransomware group’s dark web portal on August 4, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. The company is the sole South Korean entity among Gunra’s recent targets, which appear to be geographically dispersed and limited in number. The ransomware group’s targeting patterns, while leaning towards business services, technology, and manufacturing, have not yet established firm trends due to the low volume of claims. Gunra has reported 9 other victims in the 60 days leading up to this listing, indicating a less frequent operational cadence. This makes each reported victim more significant in the group’s public activity. While victims are spread across various regions including South America, Southeast Asia, and North America, there is no dominant country or region of focus. Notable recent listings that align with worldtube’s profile as a technology firm in the Asia-Pacific region include Siam Stabilizers and Chemicals Co., Ltd. / SSC, Weilhotel, Dissinger and Dissinger Law Firm, and Yuditec S.A. The scattered nature of these victims suggests a broad selection strategy rather than a targeted regional approach.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry for worldtube[.]co[.]kr returned no records within the queried sample. This sample represents a paginated portion of a larger dataset. The absence of findings does not confirm that the organization is unaffected, as credentials may exist under alternate or legacy corporate domains, or associated with regional subsidiaries. Furthermore, personal email aliases used on corporate systems, or credentials harvested prior to indexing and subsequently rotated, would not be captured by this specific lookup. Coverage gaps in Western-sourced stealer-log feeds may also explain the lack of results, as Korean-language corporate estates are often under-represented. The current finding is categorized as “no_exposure_in_sample,” and the domain will remain under observation. The absence of evidence in this sample is not definitive proof that no compromise has occurred. For ransomware groups such as Gunra, the acquisition of infostealer-harvested credentials is a common initial access vector. Threat actors or initial access brokers typically source these credentials from underground marketplaces, validate their authenticity for corporate accounts, and then gain access to systems via platforms like Microsoft 365, VPNs, or remote-access portals before deploying ransomware. Therefore, the null query result does not preclude this scenario from having occurred. Continuous monitoring of the domain and proactive credential hygiene checks are recommended.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.