Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Attack Cases in Korea Involving the Installation of Radmin and UltraVNC

0
Medium
Published: 09/04/2026 (09/04/2026, 07:52:40 UTC)
Source: AlienVault OTX General

Description

Attack campaigns targeting Korean users have been observed deploying remote control tools including Radmin and UltraVNC to compromise systems. The initial intrusion vector remains unidentified, but attackers download compressed files containing batch scripts and remote administration software. Following Radmin installation, threat actors leverage access to deploy UltraVNC alongside proxy tools such as Netch-gateway and CCProxy, ultimately utilizing compromised systems as proxy nodes. Recent variants include SoftEther VPN deployment to establish VPN servers on infected infrastructure. PowerShell scripts containing Chinese language comments, combined with tools familiar to Chinese-speaking actors, suggest attribution to Chinese threat operators. The campaigns enable both remote system control and abuse of compromised infrastructure for proxy services.

Technical Details

Author
AlienVault
Tlp
white
References
["https://asec.ahnlab.com/en/95230/"]
Adversary
null
Pulse Id
6a9a78c9a7a8e20715261f8c
Threat Score
null

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttp://103.86.86.244:800/Gateway/r.Zip
urlhttp://103.86.86.244:800/V/deploy.Ps1
urlhttp://103.86.86.244:800/Gateway/deploy_silent1.Ps1

Hash

ValueDescriptionCopy
hash02153f3fbb3611bc8b01eb347bf86c5a
hash08613b6f27bf240af3f84c88b839f034
hash0d3c1e06d135fd2018f271822335a599
hash0f906a7d2fc2b0bb73edcad8bc45bbdb
hash12cc737b0e5e9576525295da76fa53d2
hash411657f58641d1562d8248391495033b892d2c47
hash67dafd262c85ce53e711ed812e27b56a5b1068e6
hashcd036238eba83f3a7aad11a37c5e5517e57fba1f
hash6413f8681087402683d64074a7ff58d4f555566edb7a404634190c92b071a080
hash7b25c05bb456687b77750d05e9dd0684d2bcf2e012c2a172333661cdcbfbf34a
hasha1cbe89e7ba8d673adff3ea80a0ab1113c948c54990c0bb66322449b071af4b5

Domain

ValueDescriptionCopy
domainkoreakr.top
domaintt.yeyoujs.com
domaintvip.yeyoujs.com
domainwww.sheng886.top

Ip

ValueDescriptionCopy
ip103.86.86.244

Threat ID: 6a9ab102acd9273b498670b9

Added to database: 09/04/2026, 11:52:34 UTC

Last updated: 09/04/2026, 16:32:35 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses