Npcore
1 known investors
NPCore develops AI-based security solutions to detect and block new and variant malware, including network APT protection, ZombieZERO EDR for endpoint ransomware defense, and ZombieZERO XDR for automated threat detection and response. It is a South Korean information security company that also offers cloud-based security services for enterprise customers.
Also known as NPCore Β· NPCore, Inc. Β· μνΌμ½μ΄
Investors Β· 1
Company profile
researched Aug 2026NPCore, Inc. is a South Korean information security company that develops detection and response solutions for new and variant malware, marketed mainly under the ZombieZERO brand. Its portfolio spans network, email and file APT (advanced persistent threat) appliances in the ZombieZERO Inspector V4.0 series, an integrated management console, ZombieZERO EDR for endpoints, ZombieZERO SECaaS for cloud-delivered security, ZombieZERO CTI threat intelligence, ZombieZERO XDR, npFirewall and RansomZERO anti-ransomware. The company also runs malware security consulting and a security education business.
The network APT product, ZombieZERO Inspector N, extracts URLs and files from bidirectional network traffic across protocols such as HTTP, HTTPS, SMTP, POP and IMAP and applies multi-layer analysis: blacklist/whitelist patterns, an antivirus engine, YARA-rule static analysis, sandbox-based dynamic behavior analysis and reputation lookups, including a dedicated engine for non-PE files such as JavaScript, SWF and documents (HWP, MS Office, PDF, images, media). It blocks C&C communications and malicious URLs, redirects users to a landing page, supplies PCAP evidence, MITRE ATT&CK classification and syslog forwarding to SIEM/ESM systems. ZombieZERO EDR is an agent-based endpoint product that uses behavior-based rather than signature-based detection to identify and neutralize ransomware and unknown malware in real time, and integrates with the XDR layer.
ZombieZERO XDR consolidates endpoint, network and security-device telemetry in one detection framework and combines active data collection with automated threat determination (described by the company as AI-TIP), aiming to let organizations automatically classify attackers, attack types and countermeasures without dedicated analysts. Outputs include incident information, malware similarity, threat site prediction, attack technique and attack group attribution derived from threat hunting. NPCore positions the platform for institutions and enterprises operating multiple security devices or security operations centers, and also describes a threat intelligence data platform offered via portal, including free access for verified white-hat researchers, non-profit research institutes and educational institutions.
Business model
NPCore licenses and sells security products β network/email/file APT appliances, endpoint EDR agents, XDR and firewall software β to organizations, complemented by cloud-delivered security-as-a-service (ZombieZERO SECaaS), threat intelligence (ZombieZERO CTI) offered as a service or portal, malware security consulting and a security education business. A dedicated malware analysis team provides manual analysis reports and incident response support alongside the products.
Product sales and service delivery: security appliance and software solutions sold to institutions and enterprises, cloud-based SECaaS, threat intelligence services (including a portal offered to security control providers and enterprises, with free access tiers for non-profit users), consulting and security training.
Traction
The company states that its ZombieZERO two-level APT defense has been supplied to governments, financial institutions, universities and enterprises. Product certifications include GS Certification, international CC EAL2 and a Korean National Intelligence Service security function certificate for ZombieZERO XDR (May 2026), and RansomZERO won an IR52 Jang Young Shil Award (April 2026).
Latest developments
In 2026 the company obtained a National Intelligence Service security function certificate for its XDR security solution (May 2026), received an IR52 Jang Young Shil Award for the RansomZERO anti-ransomware product (April 2026), ran a subway booth promotional campaign (March 2026), and announced participation in Vietnam Security Summit 2026 (May 2026) to present next-generation XDR and ransomware response technology. A shareholder record date notice was posted for May 2026.
βΈFull profile β market position, technology, go-to-market, geography, history
Market position
NPCore describes itself as a leading company in detection of new and variant malware and a specialist in APT response and EDR, and positions itself as a representative Korean information security company expanding into cloud-based security services. It holds GS Certification and international CC (EAL2) certification, obtained a National Intelligence Service security function certificate for its XDR product, and its RansomZERO anti-ransomware product received an IR52 Jang Young Shil Award.
Differentiation claims center on behavior-based, AI-assisted detection instead of signature matching; a dual-layer defense covering both network and endpoint with correlation analysis between APT products; multi-engine analysis including dedicated non-executable file handling and virtual-machine bypass prevention; automated threat determination in XDR intended to work without specialist analysts; and an in-house malware expert analysis team providing manual reports.
Technology
Core technology is AI-based behavior detection combined with a two-level defense architecture covering network and endpoint. Network analysis uses virtual analysis machines (sandboxes) with virtual-machine bypass prevention, YARA static rules, antivirus engines, reputation analysis and non-PE file engines, with collection-dedicated acceleration boards for traffic capture and SSL decryption integration for encrypted traffic. Pattern feeds include KISA C-TAS and the Cyber Safety Center domestically and Bitdefender, VirusSign and VirusTotal internationally. Endpoint detection is behavior-based to catch unknown threats, and the XDR layer applies automated threat determination (AI-TIP) plus AI machine learning (supervised and unsupervised) correlation across endpoint, network and security-device data.
Go-to-market
The company sells through domestic and international distributors and channel partners, and maintains dedicated technical support and SECaaS sales support lines. It markets in Korean, English, Japanese and Vietnamese, exhibits at regional security events such as Vietnam Security Summit 2026, and uses certifications (GS Certification, CC EAL2, National Intelligence Service security function certificate) and awards as procurement credentials. Offline promotion has included a subway booth campaign.
Public institutions, financial firms, universities and enterprises, both in Korea and abroad; specifically organizations that must monitor multiple security devices, need incident root-cause analysis, or want to operate a security operations center with limited specialist staff. Threat intelligence users include security control service providers, information security operations centers, corporate security managers and incident response analysis centers, plus white-hat researchers and educational institutions on a non-profit basis.
Geography
Headquartered in Seoul, South Korea, at Geumgang Penterium IT Tower, 171 Dangsan-ro, Yeongdeungpo-gu. The website is published in Korean, English, Japanese and Vietnamese, and the company sells via domestic and overseas distributors, with activity in Vietnam including participation in Vietnam Security Summit 2026.
History
NPCore was established in 2008 to develop specialized malware detection and response solutions for an antivirus-centric security market, and subsequently built the ZombieZERO line providing two-level defense against APT attacks for government, financial, university and enterprise customers. The product range has since expanded from network APT appliances to endpoint EDR, SECaaS, CTI, XDR, npFirewall and RansomZERO, alongside a security education business. Recent milestones include obtaining a National Intelligence Service security function certificate for its XDR solution and an IR52 Jang Young Shil Award for RansomZERO in 2026.
Compiled by commissioned research from 6 cited public sources β announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed β not independently audited.
Timeline Β· 5
launches, deals, and filingsNPCore announced it would take part in Vietnam Security Summit 2026 to showcase its next-generation XDR and ransomware response technologies.
NPCore posted a public notice setting a record date for determining shareholders.
NPCore announced that its XDR security solution obtained a security function confirmation certificate from Korea's National Intelligence Service.
NPCore's anti-ransomware solution RansomZERO received the IR52 Jang Young Shil Award.
The company ran a promotional booth in a subway station under the theme of guiding customers to the 'final destination of security'.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
βΈResearch sources Β· 6
primary sources listed
- Npcorenpcore.com Β· web
6 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Npcore do?
- South Korean security vendor building AI behavior-based APT, EDR and XDR solutions under the ZombieZERO brand.
- Who are Npcore's investors?
- Npcore's investors include Colopl Next.
