Skip to content

Hackers Use RedLine C2 Infrastructure to Target South Korean Maritime Industry

Gbhackers •Mayura Kathir • July 6, 2026

A single RedLine Stealer command-and-control (C2) indicator has revealed a focused spear-phishing campaign targeting the South Korean maritime industry, exposing a cluster of attacker-owned domains and mail infrastructure used to distribute credential-stealing payloads. The initial signal originated from a VMRay UniqueSignal feed: an IP observed running RedLine activity on a non-standard high port (194[.]156.79.122:55615). That […]

Extracted Entities

Attack Types (1)

IP Addresses (1)

Malware (1)