> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Threat Actor Selling Root Access to South Korean Government Server With Lateral Movement to 42 Internal Hosts
- URL: https://darkwebinformer.com/threat-actor-selling-root-access-to-south-korean-government-server-with-lateral-movement-to-42-internal-hosts/
- Published: 2026-03-11T15:22:58.000Z
- Updated: 2026-03-11T16:07:18.000Z
- Author: Dark Web Informer
- Tags: Initial Access

Dark Web Informer - Cyber Threat Intelligence 

# Threat Actor Selling Root Access to South Korean Government Server With Lateral Movement to 42 Internal Hosts

March 11, 2026 - 11:32:55 AM UTC 

![South Korea](https://flagcdn.com/20x15/kr.png)South Korea 

Government 

Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. 

[ View API](https://darkwebinformer.com/api-details/) 

 Unlock Exclusive Cyber Threat Intelligence

Powered by DarkWebInformer.com

Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously.

[ Subscribe Now](https://darkwebinformer.com/pricing) 

## Quick Facts

Date & Time 2026-03-11 11:32:55 UTC 

Threat Actor zSenior 

Victim Country ![South Korea](https://flagcdn.com/20x15/kr.png)South Korea 

Industry Government 

Victim Domain \*.go.kr 

Access Level Root 

Category Initial Access 

Severity Critical 

Network Open Web 

Price Waiting Offers 

##  Incident Overview

A threat actor operating under the handle zSenior is selling root-level access to a South Korean government server hosted on a \*.go.kr domain, the official top-level domain reserved for South Korean government agencies. The actor claims to have completed full privilege escalation and states that pivoting to 42 internal live hosts from the compromised server should be straightforward.

  
Beyond the initial root access, the actor reports having obtained PostgreSQL database superuser access on a second internal server at 192.168.0.147, which they describe as containing PII. They also believe this secondary server may be vulnerable to remote code execution, further expanding the potential attack surface. The compromised server is running CentOS and has been online continuously for 1,642 days, with disk usage showing a 50GB root partition and a 142GB home partition at 55% capacity.

  
The actor emphasizes they are selling full access only and explicitly states this is not for traffic, database, or malware distribution. Proof is available upon request, pricing is open to offers, and escrow is accepted. This represents a significant national security concern given the government domain and the extensive lateral movement potential across dozens of internal systems.

### Claim URL - For Subscribers Only

The claim URL for this listing can be found on the **Threat Feed** or **Ransomware Feed** for subscribers.

[ Subscribe Now](https://darkwebinformer.com/pricing) 

##  Image Preview

[![Forum listing showing root access to South Korean government server for sale with lateral movement to 42 internal hosts](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/39387827165773573299.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/39387827165773573299.png) 

Dark Web Informer © 2026 | Cyber Threat Intelligence  
[DarkWebInformer.com](https://darkwebinformer.com/)