logo

Analysis of Attack Case Installing SoftEther VPN on Korean ERP Server

ID: 072260fa-76ee-5c60-8df3-24187ad271e6

STIX ID: report--072260fa-76ee-5c60-8df3-24187ad271e6

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-06-17

Date Updated: 2026-04-26

Author: Sanseo

...
...

AhnLab ASEC discovered an attack on a Korean company's ERP server where the attacker abused an exposed MS-SQL service to gain access, deployed a web shell, exfiltrated credentials (Mimikatz-related activity), and installed SoftEther VPN (configured in cascade mode) to turn the host into a relay/C2 infrastructure. The report provides command logs, downloader behavior, file detections, MD5 hashes, and URLs used to deliver payloads, and recommends stronger password management and network access controls for database servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.