Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea
ID: d2520110-4c23-536b-a3a5-cb3dc7344d13
STIX ID: report--d2520110-4c23-536b-a3a5-cb3dc7344d13
Feed Name: ASEC
ASEC identified an active campaign by the Larva-26010 threat actor that compromises Korean web and MS-SQL servers to install SoftEther VPN (disguised as vmtoolsd.Exe and deployed under ProgramData) and additional persistence/backdoors (web shells, CLR SqlShell). The report documents discovery and installation commands (PowerShell, certutil, curl), registry changes to enable WDigest credential exposure, use of cascade VPN configurations to obscure C2, provides IoCs (IPs, URLs, MD5s), and recommends patching, input validation, permission restrictions, and AV updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
