Attack Cases in Korea Involving the Installation of Radmin and UltraVNC

Attack Cases in Korea Involving the Installation of Radmin and UltraVNC
ASEC found attack cases where threat actors used Radmin and UltraVNC to take over infected systems, then deployed Netch, CCProxy, and SoftEther VPN to turn them into proxy nodes and VPN servers. The activity involved downloads from 103.86.86[.]244 and used Chinese-language scripts and configuration files, suggesting a Chinese-speaking operator. #Radmin #UltraVNC #Netch #CCProxy #SoftEtherVPN #103.86.86.244

Keypoints

  • The initial intrusion method remains unknown, but PowerShell used curl to download a compressed file from 103.86.86[.]244:800.
  • The archive contained a batch script, a REG file, and Radmin, which was installed and configured with attacker-specific settings including the ID “ruxin.”
  • After gaining control through Radmin, the attacker deployed UltraVNC using a PowerShell-based installer and related watchdog tasks/services.
  • UltraVNC traffic showed registration, heartbeat, and password confirmation APIs used to manage infected systems remotely.
  • The attacker also installed proxy tools, including Netch-gateway and CCProxy, to use compromised hosts as proxy nodes.
  • Recent cases additionally show SoftEther VPN being installed so infected systems can be abused as VPN servers.
  • Chinese comments, Chinese configuration content, and Chinese-language proxy pages suggest the threat actor may be a Chinese speaker.

MITRE Techniques

  • [T1059.001 ] PowerShell – Used to download and execute multiple scripts and payloads (‘PowerShell used the curl command to download a compressed file’ / ‘PowerShell -WindowStyle Hidden -NoProfile -ExecutionPolicy Bypass -Command “irm … | iex”’)
  • [T1105 ] Ingress Tool Transfer – Downloaded archives, scripts, and executables from remote servers for installation (‘download a compressed file from the following Path’ / ‘downloads UltraVNC-related files from the download server’)
  • [T1219 ] Remote Access Software – Installed and used Radmin and UltraVNC to remotely control infected systems (‘installed Radmin—a remote control tool—and then installed UltraVNC’ / ‘the threat actor can then connect … and remotely control the infected system’)
  • [T1543.003 ] Create or Modify System Process: Windows Service – Registered services such as WpnUserHost to run the installer as a service (‘it registers a service named “WpnUserHost” so that the Installer can run as a service’)
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Created watchdog tasks to repeatedly download and run repair scripts (‘registers a task named “WpnUserHost_MutualWatchdog”’ / ‘WpnUserHost_HourlyWatchdog’)
  • [T1021.001 ] Remote Services: RDP – Leveraged remote desktop-style access through Radmin Server and Viewer (‘Radmin Server … and use Radmin Viewer to perform System Control’)
  • [T1090 ] Proxy – Deployed Netch and CCProxy to make infected systems act as proxy nodes (‘installed Netch and CCProxy to use the infected systems as proxy nodes’)
  • [T1090.001 ] Proxy: Internal Proxy – Used SOCKS proxy functionality in CCProxy and Netch-gateway to relay traffic (‘enables a SOCKS proxy through port 49661’ / ‘supports the SOCKS5, Shadowsocks, and KCP protocols’)
  • [T1133 ] External Remote Services – Set up SoftEther VPN so attackers could use compromised hosts as VPN servers (‘installed SoftEther VPN to exploit the infected systems as VPN servers’)
  • [T1027 ] Obfuscated Files or Information – Disguised payloads and installer names, including svchost.Exe and hidden execution (‘svchost.Exe (which is actually SoftEther VPN disguised as a legitimate Microsoft program)’)

Indicators of Compromise

  • [IP address] download and C&C infrastructure – 103.86.86[.]244, 103.86.86[.]244:800
  • [FQDN] C&C and proxy-related domains – tt[.]yeyoujs[.]com, koreakr[.]top
  • [URL] payload and configuration downloads – hxxp://103.86.86[.]244:800/Gateway/r.Zip, http[:]//103[.]86[.]86[.]244/gateway/ag[.]exe
  • [File name] installer and script files – 11.Bat, deploy.Ps1
  • [File name] UltraVNC-related components – svchost.Exe, web.Ini
  • [File name] proxy and VPN files – config.Json, vpn_server.Config
  • [File hash MD5] samples referenced by ASEC – 02153f3fbb3611bc8b01eb347bf86c5a, 08613b6f27bf240af3f84c88b839f034, and 3 more hashes


Read more: https://asec.ahnlab.com/en/95230/