C
月内に
韓国国内を標的とした、RadminおよびUltraVNCなどのリモート制御ツールを悪用する攻撃
📌 一言でいうと
韓国国内を標的とした、RadminおよびUltraVNCなどのリモート制御ツールを悪用する攻撃が確認されました。攻撃者はPowerShellを用いて悪意のあるファイルをダウンロードし、感染システムをリモート制御下に置いた後、NetchやCCProxy、SoftEther VPNをインストールしてプロキシサーバーやVPNサーバーとして悪用しています。初期侵入経路は不明ですが、特定のレジストリ設定を用いて攻撃者が容易にアクセスできるよう構成されています。
🔍該当判定
- 社内でリモート操作ソフト「Radmin」をインストールして利用している
- 社内でリモート操作ソフト「UltraVNC」をインストールして利用している
- 社内でプロキシサーバーソフト「CCProxy」や「Netch」をインストールして利用している
- 社内でVPNサーバーソフト「SoftEther VPN」をインストールして利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. 不審なPowerShellスクリプトの実行を制限し、監視を強化すること。2. Radmin, UltraVNC, SoftEther VPNなどのリモート制御・VPNツールの未承認インストールを禁止し、検知すること。3. 外部への不審な通信(特にプロキシやVPNに関連するポート)を遮断すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Radmin/UltraVNC等を悪用したプロキシ化攻撃について
お疲れさまです。韓国国内で観測されたリモート制御ツール悪用事例に関する情報共有です。
■ 概要
攻撃者がRadminおよびUltraVNCをインストールしてシステム制御権を奪取し、さらにNetch, CCProxy, SoftEther VPNを導入することで、感染端末をプロキシサーバーやVPNサーバーとして悪用する事例が確認されています。
■ 影響範囲
- Windows OS(Radmin, UltraVNC, SoftEther VPN等のツールがインストール可能な環境)
■ 対応手順
1. 以下のIOC(C2サーバー)への通信ログを確認し、不審な通信がないか調査してください。
- 103.86.86[.]244
2. 端末内で「C:\Intel\RServer」などの不審なディレクトリや、未承認のリモート制御ツールのインストール状況を確認してください。
3. PowerShellによる外部からのzipファイルダウンロード(Curl等)を監視・制限してください。
■ 参考情報
- AhnLab SEcurity intelligence Center (ASEC) レポート
対応優先度: 中
対応期限: 速やかに確認
お疲れさまです。韓国国内で観測されたリモート制御ツール悪用事例に関する情報共有です。
■ 概要
攻撃者がRadminおよびUltraVNCをインストールしてシステム制御権を奪取し、さらにNetch, CCProxy, SoftEther VPNを導入することで、感染端末をプロキシサーバーやVPNサーバーとして悪用する事例が確認されています。
■ 影響範囲
- Windows OS(Radmin, UltraVNC, SoftEther VPN等のツールがインストール可能な環境)
■ 対応手順
1. 以下のIOC(C2サーバー)への通信ログを確認し、不審な通信がないか調査してください。
- 103.86.86[.]244
2. 端末内で「C:\Intel\RServer」などの不審なディレクトリや、未承認のリモート制御ツールのインストール状況を確認してください。
3. PowerShellによる外部からのzipファイルダウンロード(Curl等)を監視・制限してください。
■ 参考情報
- AhnLab SEcurity intelligence Center (ASEC) レポート
対応優先度: 中
対応期限: 速やかに確認
Subject: [Intel] Attack utilizing Radmin/UltraVNC for Proxy Infrastructure
Dear Team,
We are sharing information regarding a recent campaign targeting South Korea that repurposes infected systems as proxy nodes.
■ Overview
Attackers are deploying Radmin and UltraVNC to gain remote control of systems. Once compromised, they install Netch, CCProxy, and SoftEther VPN to transform the infected hosts into proxy or VPN servers for further malicious activities.
■ Scope
- Windows environments where remote administration tools can be installed.
■ Action Items
1. Check network logs for communication with the following IOC:
- 103.86.86[.]244
2. Scan for unauthorized installations of Radmin, UltraVNC, or SoftEther VPN, and check for suspicious paths such as "C:\Intel\RServer".
3. Monitor and restrict PowerShell-based downloads (e.g., via Curl) of executable archives from external sources.
■ Reference
- AhnLab SEcurity intelligence Center (ASEC)
Priority: Medium
Deadline: Immediate review
Dear Team,
We are sharing information regarding a recent campaign targeting South Korea that repurposes infected systems as proxy nodes.
■ Overview
Attackers are deploying Radmin and UltraVNC to gain remote control of systems. Once compromised, they install Netch, CCProxy, and SoftEther VPN to transform the infected hosts into proxy or VPN servers for further malicious activities.
■ Scope
- Windows environments where remote administration tools can be installed.
■ Action Items
1. Check network logs for communication with the following IOC:
- 103.86.86[.]244
2. Scan for unauthorized installations of Radmin, UltraVNC, or SoftEther VPN, and check for suspicious paths such as "C:\Intel\RServer".
3. Monitor and restrict PowerShell-based downloads (e.g., via Curl) of executable archives from external sources.
■ Reference
- AhnLab SEcurity intelligence Center (ASEC)
Priority: Medium
Deadline: Immediate review