South Korea (KR) Threat Intelligence

KR

South Korea has 62,508 malicious IP addresses with 3,555,550 abuse reports. Top threat categories include tcp scan, high threat, suspicious activity, malware distribution, severe abuse. Top attacking networks: Korea Telecom (22,205 IPs), LARUS Limited (11,235 IPs), Microsoft Corporation (2,918 IPs). Data collected since 2022-12-19, last activity 2026-10-04.

Threat Assessment: South Korea shows substantial cyber threat activity, ranking among the top threat source countries worldwide. The dominant attack types are tcp scan, high threat, suspicious activity. The majority of threats originate from networks operated by Korea Telecom and LARUS Limited.

Total Reports
3,555,550
Unique IPs
62,508
First Seen
2022-12-19
Last Activity
2026-10-04

Top Threat Categories

Tcp Scan 572,319
High Threat 264,353
Suspicious Activity 256,002
Malware Distribution 81,137
Severe Abuse 30,454

Top Attacking Networks

AS4766 Korea Telecom
22,205 IPs
AS17561 LARUS Limited
11,235 IPs
AS8075 Microsoft Corporation
2,918 IPs

Most Reported IPs in South Korea

211.106.133.202 1,420 reports
211.223.107.86 1,404 reports
118.37.214.187 1,400 reports
222.108.100.117 1,386 reports
49.247.37.22 1,379 reports

Access this data via API

Get South Korea threat intelligence programmatically.

curl https://ip.wayscloud.services/api/country/KR

View full API documentation

See how we classify and verify threats →

Check any IP from South Korea

Look up threat intelligence for a specific IP address.

Related: Country Threat Ranking Country Risk Trends → Top Malicious IPs → AS4766 Intelligence AS17561 Intelligence AS8075 Intelligence Global Attack Trends Detect Malicious Traffic

Loading threat intelligence data...