ASEC found attack cases where threat actors used Radmin and UltraVNC to take over infected systems, then deployed Netch, CCProxy, and SoftEther VPN to turn them into proxy nodes and VPN servers. The activity involved downloads from 103.86.86[.]244 and used Chinese-language scripts and configuration files, suggesting a Chinese-speaking operator. #Radmin #UltraVNC #Netch #CCProxy #SoftEtherVPN #103.86.86.244
Keypoints
- The initial intrusion method remains unknown, but PowerShell used curl to download a compressed file from 103.86.86[.]244:800.
- The archive contained a batch script, a REG file, and Radmin, which was installed and configured with attacker-specific settings including the ID âruxin.â
- After gaining control through Radmin, the attacker deployed UltraVNC using a PowerShell-based installer and related watchdog tasks/services.
- UltraVNC traffic showed registration, heartbeat, and password confirmation APIs used to manage infected systems remotely.
- The attacker also installed proxy tools, including Netch-gateway and CCProxy, to use compromised hosts as proxy nodes.
- Recent cases additionally show SoftEther VPN being installed so infected systems can be abused as VPN servers.
- Chinese comments, Chinese configuration content, and Chinese-language proxy pages suggest the threat actor may be a Chinese speaker.
MITRE Techniques
- [T1059.001 ] PowerShell â Used to download and execute multiple scripts and payloads (âPowerShell used the curl command to download a compressed fileâ / âPowerShell -WindowStyle Hidden -NoProfile -ExecutionPolicy Bypass -Command âirm ⌠| iexââ)
- [T1105 ] Ingress Tool Transfer â Downloaded archives, scripts, and executables from remote servers for installation (âdownload a compressed file from the following Pathâ / âdownloads UltraVNC-related files from the download serverâ)
- [T1219 ] Remote Access Software â Installed and used Radmin and UltraVNC to remotely control infected systems (âinstalled Radminâa remote control toolâand then installed UltraVNCâ / âthe threat actor can then connect ⌠and remotely control the infected systemâ)
- [T1543.003 ] Create or Modify System Process: Windows Service â Registered services such as WpnUserHost to run the installer as a service (âit registers a service named âWpnUserHostâ so that the Installer can run as a serviceâ)
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Created watchdog tasks to repeatedly download and run repair scripts (âregisters a task named âWpnUserHost_MutualWatchdogââ / âWpnUserHost_HourlyWatchdogâ)
- [T1021.001 ] Remote Services: RDP â Leveraged remote desktop-style access through Radmin Server and Viewer (âRadmin Server ⌠and use Radmin Viewer to perform System Controlâ)
- [T1090 ] Proxy â Deployed Netch and CCProxy to make infected systems act as proxy nodes (âinstalled Netch and CCProxy to use the infected systems as proxy nodesâ)
- [T1090.001 ] Proxy: Internal Proxy â Used SOCKS proxy functionality in CCProxy and Netch-gateway to relay traffic (âenables a SOCKS proxy through port 49661â / âsupports the SOCKS5, Shadowsocks, and KCP protocolsâ)
- [T1133 ] External Remote Services â Set up SoftEther VPN so attackers could use compromised hosts as VPN servers (âinstalled SoftEther VPN to exploit the infected systems as VPN serversâ)
- [T1027 ] Obfuscated Files or Information â Disguised payloads and installer names, including svchost.Exe and hidden execution (âsvchost.Exe (which is actually SoftEther VPN disguised as a legitimate Microsoft program)â)
Indicators of Compromise
- [IP address] download and C&C infrastructure â 103.86.86[.]244, 103.86.86[.]244:800
- [FQDN] C&C and proxy-related domains â tt[.]yeyoujs[.]com, koreakr[.]top
- [URL] payload and configuration downloads â hxxp://103.86.86[.]244:800/Gateway/r.Zip, http[:]//103[.]86[.]86[.]244/gateway/ag[.]exe
- [File name] installer and script files â 11.Bat, deploy.Ps1
- [File name] UltraVNC-related components â svchost.Exe, web.Ini
- [File name] proxy and VPN files â config.Json, vpn_server.Config
- [File hash MD5] samples referenced by ASEC â 02153f3fbb3611bc8b01eb347bf86c5a, 08613b6f27bf240af3f84c88b839f034, and 3 more hashes
Read more: https://asec.ahnlab.com/en/95230/