South Korea (KR) Threat Intelligence

KR

South Korea has 49,225 malicious IP addresses with 2,339,086 abuse reports. Top threat categories include suspicious activity, severe abuse, ssh bruteforce, moderate threat, high threat. Top attacking networks: Korea Telecom (14,940 IPs), LARUS Limited (10,213 IPs), Microsoft Corporation (2,604 IPs). Data collected since 2022-12-19, last activity 2026-07-05.

Threat Assessment: South Korea shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are suspicious activity, severe abuse, ssh bruteforce. The majority of threats originate from networks operated by Korea Telecom and LARUS Limited.

Total Reports
2,339,086
Unique IPs
49,225
First Seen
2022-12-19
Last Activity
2026-07-05

Top Threat Categories

Suspicious Activity 60,661
Severe Abuse 30,454
Ssh Bruteforce 7,360
Moderate Threat 6,990
High Threat 4,650

Top Attacking Networks

AS4766 Korea Telecom
14,940 IPs
AS17561 LARUS Limited
10,213 IPs
AS8075 Microsoft Corporation
2,604 IPs

Most Reported IPs in South Korea

211.37.174.180 420 reports
14.63.196.175 418 reports
222.232.176.7 418 reports
118.37.214.187 408 reports
1.238.106.229 408 reports

Access this data via API

Get South Korea threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/KR

View full API documentation

See how we classify and verify threats →

Check any IP from South Korea

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS4766 Intelligence AS17561 Intelligence AS8075 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...