Larva-25012 is a financially motivated cybercriminal threat actor associated with proxyjacking campaigns that target users seeking cracked or pirated software. The actor is known for distributing trojanized software installers, particularly fake Notepad++ packages, through deceptive advertising pages and fraudulent download portals. Activity has been observed primarily against users in South Korea. Larva-25012’s operations bundle legitimate application components with hidden malware and rely on DLL side-loading to execute malicious code while preserving the appearance of a normal installation. The actor has delivered payloads in installer and archive formats, using staged loaders that decrypt in-memory payloads, install additional runtime components such as NodeJS or Python, and deploy downloader functionality that retrieves follow-on instructions from command-and-control infrastructure. Persistence has been established through Windows Task Scheduler using task names designed to appear benign or security-related. The actor’s malware has evolved from .NET-based tooling to C++ and Python variants and has incorporated more advanced defense-evasion and execution techniques, including shellcode deployment, process injection into legitimate Windows processes, and running proxyware from within Windows Explorer. Reported payloads include proxyware such as Infatica and DigitalPulse, indicating a monetization model centered on covert resale of victim bandwidth rather than ransomware or data theft. Known aliases are limited to formatting variants of the same name, including Larva-25012 and larva_25012.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Runs a proxyjacking campaign disguised as trojanized Notepad++ installers distributed via fake/cracked-software download portals. Establishes persistence via Windows Task Scheduler, uses DLL side-loading and process injection (notably into explorer.exe), deploys loaders (including JavaScript/Python variants) to install proxyware (Infatica, DigitalPulse) that monetizes victims’ internet bandwidth.
Monetization-focused malware operations distributing proxyware via trojanized/fake software installers (Notepad++ lure), using downloader malware and persistence to install bandwidth-reselling proxyware on victim systems, primarily targeting South Korea.
Distributes trojanized installers (e.g., fake Notepad++ and other cracked software) to proxyjack victims by installing proxyware for bandwidth monetization; uses DLL side-loading and loader/downloader chains to deploy proxy agents and maintain persistence while evading defenses.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.