Quick Summary
AllegedExecutive Summary
BlackLocks ransomware actors listed Gwangmyeong Industrial Co. (광명산업(주)), a South Korean manufacturer of industrial components and materials, on their dark web portal on September 5, 2026. This listing was identified by SOCRadar’s Dark Web Monitoring service. The company operates within the manufacturing sector in South Korea. In SOCRadar’s observed 60-day window, Gwangmyeong Industrial Co. is the sole victim listed by BlackLocks, with the attack targeting the manufacturing sector in South Korea. This narrow focus suggests deliberate targeting rather than a widespread campaign. East Asian industrial manufacturers have become increasingly prominent targets within the ransomware landscape, and BlackLocks appears to be strategically positioning itself in this area. Further activity will likely reveal more about the group’s typical targeting patterns.
Technical Analysis
Stealer-log telemetry queried by SOCRadar for the domain kmin[.]co.kr returned no records within the analyzed dataset. However, this absence of evidence does not definitively rule out credential-based initial access. It is possible that credentials may exist in data feeds outside the scope of this query, may be associated with personal email aliases, or were compromised and subsequently rotated before being indexed. Therefore, continued monitoring of the corporate domain is strongly advised. The lack of stealer-log records does not preclude the possibility of other initial access vectors being utilized by threat actors. Credentials harvested through infostealer malware can provide a direct path for attackers to gain unauthorized access to corporate networks, facilitating the deployment of ransomware. While this specific telemetry did not yield positive results for Gwangmyeong Industrial Co., the potential for credential exposure through other means remains a concern. Continued dark web monitoring for Gwangmyeong Industrial Co. is recommended. Proactive credential hygiene checks, including password rotation and multi-factor authentication reviews, should be a priority. Additionally, monitoring activity across Microsoft 365, VPNs, and remote-access portals is crucial to detect any suspicious or unauthorized access attempts.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.