Attack Cases in Korea Involving the Installation of Radmin and UltraVNC
Attack campaigns targeting Korean users have been observed deploying remote control tools including Radmin and UltraVNC to compromise systems. The initial intrusion vector remains unidentified, but attackers download compressed files containing batch scripts and remote administration software. Following Radmin installation, threat actors leverage access to deploy UltraVNC alongside proxy tools such as Netch-gateway and CCProxy, ultimately utilizing compromised systems as proxy nodes. Recent variants include SoftEther VPN deployment to establish VPN servers on infected infrastructure. PowerShell scripts containing Chinese language comments, combined with tools familiar to Chinese-speaking actors, suggest attribution to Chinese threat operators. The campaigns enable both remote system control and abuse of compromised infrastructure for proxy services.
Indicators of Compromise
- url: http://103.86.86.244:800/Gateway/r.Zip
- url: http://103.86.86.244:800/V/deploy.Ps1
- url: http://103.86.86.244:800/Gateway/deploy_silent1.Ps1
- hash: 02153f3fbb3611bc8b01eb347bf86c5a
- hash: 08613b6f27bf240af3f84c88b839f034
- hash: 0d3c1e06d135fd2018f271822335a599
- hash: 0f906a7d2fc2b0bb73edcad8bc45bbdb
- hash: 12cc737b0e5e9576525295da76fa53d2
- domain: koreakr.top
- domain: tt.yeyoujs.com
- domain: tvip.yeyoujs.com
- domain: www.sheng886.top
- ip: 103.86.86.244
- hash: 411657f58641d1562d8248391495033b892d2c47
- hash: 67dafd262c85ce53e711ed812e27b56a5b1068e6
- hash: cd036238eba83f3a7aad11a37c5e5517e57fba1f
- hash: 6413f8681087402683d64074a7ff58d4f555566edb7a404634190c92b071a080
- hash: 7b25c05bb456687b77750d05e9dd0684d2bcf2e012c2a172333661cdcbfbf34a
- hash: a1cbe89e7ba8d673adff3ea80a0ab1113c948c54990c0bb66322449b071af4b5
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC
Description
Attack campaigns targeting Korean users have been observed deploying remote control tools including Radmin and UltraVNC to compromise systems. The initial intrusion vector remains unidentified, but attackers download compressed files containing batch scripts and remote administration software. Following Radmin installation, threat actors leverage access to deploy UltraVNC alongside proxy tools such as Netch-gateway and CCProxy, ultimately utilizing compromised systems as proxy nodes. Recent variants include SoftEther VPN deployment to establish VPN servers on infected infrastructure. PowerShell scripts containing Chinese language comments, combined with tools familiar to Chinese-speaking actors, suggest attribution to Chinese threat operators. The campaigns enable both remote system control and abuse of compromised infrastructure for proxy services.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://asec.ahnlab.com/en/95230/"]
- Adversary
- null
- Pulse Id
- 6a9a78c9a7a8e20715261f8c
- Threat Score
- null
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://103.86.86.244:800/Gateway/r.Zip | — | |
urlhttp://103.86.86.244:800/V/deploy.Ps1 | — | |
urlhttp://103.86.86.244:800/Gateway/deploy_silent1.Ps1 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash02153f3fbb3611bc8b01eb347bf86c5a | — | |
hash08613b6f27bf240af3f84c88b839f034 | — | |
hash0d3c1e06d135fd2018f271822335a599 | — | |
hash0f906a7d2fc2b0bb73edcad8bc45bbdb | — | |
hash12cc737b0e5e9576525295da76fa53d2 | — | |
hash411657f58641d1562d8248391495033b892d2c47 | — | |
hash67dafd262c85ce53e711ed812e27b56a5b1068e6 | — | |
hashcd036238eba83f3a7aad11a37c5e5517e57fba1f | — | |
hash6413f8681087402683d64074a7ff58d4f555566edb7a404634190c92b071a080 | — | |
hash7b25c05bb456687b77750d05e9dd0684d2bcf2e012c2a172333661cdcbfbf34a | — | |
hasha1cbe89e7ba8d673adff3ea80a0ab1113c948c54990c0bb66322449b071af4b5 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainkoreakr.top | — | |
domaintt.yeyoujs.com | — | |
domaintvip.yeyoujs.com | — | |
domainwww.sheng886.top | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip103.86.86.244 | — |
Threat ID: 6a9ab102acd9273b498670b9
Added to database: 09/04/2026, 11:52:34 UTC
Last updated: 09/04/2026, 16:32:35 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.