Larva-25012 is a financially motivated cybercriminal group active since at least 2025 that conducts proxyjacking operations, principally against systems in South Korea. The group lures users seeking cracked or pirated software through deceptive advertisements, fraudulent download portals, and trojanized installers impersonating legitimate applications, including Notepad++. Earlier activity also used free video-download sites and software-cleanup lures. Larva-25012 uses DLL side-loading and staged loaders, including DPLoader, to establish execution and deploy unauthorized bandwidth-sharing software. DPLoader exists in JavaScript and Python variants, gathers host information, communicates with command-and-control infrastructure, receives PowerShell commands, and persists through Windows Scheduled Tasks. The group has deployed proxyware associated with DigitalPulse, Honeygain, Infatica, SOAX, Appsalt, and IPRoyal, monetizing victim internet bandwidth through attacker-controlled accounts or tokens. Its operations employ obfuscation, scheduled-task persistence, masquerading as Windows or Microsoft components, security-tool impairment, and process injection, including into Windows Explorer. Larva-25012 has also used PowerShell to stage components and weaken Microsoft Defender protections.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal proxyjacking operation that monetizes compromised hosts' internet bandwidth by installing proxyware. The campaign distributes proxyware through deceptive download sources and uses an already-installed DPLoader for renewed deployment.
Conducts proxyjacking operations for revenue by installing proxyware on victim systems without consent. The actor previously used pop-up advertisements on YouTube-download sites, GitHub repositories posing as Steam cleanup tools, and illegal software-crack download pages. In the current activity, it uses the DPLoader JavaScript loader to download PowerShell scripts that deploy DigitalPulse, SOAX, Appsalt, or IPRoyal proxyware.
Runs a proxyjacking campaign disguised as trojanized Notepad++ installers distributed via fake/cracked-software download portals. Establishes persistence via Windows Task Scheduler, uses DLL side-loading and process injection (notably into explorer.exe), deploys loaders (including JavaScript/Python variants) to install proxyware (Infatica, DigitalPulse) that monetizes victims’ internet bandwidth.
Monetization-focused malware operations distributing proxyware via trojanized/fake software installers (Notepad++ lure), using downloader malware and persistence to install bandwidth-reselling proxyware on victim systems, primarily targeting South Korea.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.