Larva-24009 is a phishing-driven malware operator active since at least 2023. The actor has targeted users in South Korea and internationally, with lures themed around business documents, resumes, surveys, and blockchain-related material, and appears to focus at least in part on enterprise victims. Initial access is achieved through phishing emails carrying malicious shortcut files disguised as documents. Execution typically launches obfuscated PowerShell, opens a decoy document, and retrieves additional payloads from attacker-controlled infrastructure. Observed Larva-24009 activity includes multi-stage PowerShell malware used for payload delivery, host profiling, screenshot capture, and defense evasion, including attempts to disable Windows Defender. The actor has established persistence through scheduled tasks and has deployed remote-access tooling including QuasarRAT and UltraVNC Server; use of RDP has also been assessed in connection with the operation. Post-compromise activity includes surveillance and credential collection through commodity utilities and custom tooling, including browser credential theft, bookmark collection, recovery of stored network passwords, keylogging, and collection of user activity data. A newer Notifier malware variant associated with the operation has been used to report infection status via the Telegram API. Additional observed tradecraft includes creation of a backdoor local account to preserve access. Larva-24009 has also been tracked in overlapping reporting under the campaign name HeptaX. The actor’s operations are consistent with a financially or operationally motivated intrusion set focused on malware installation, persistent access, and information theft, but publicly available facts do not firmly establish state sponsorship.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting phishing email campaigns since at least 2023 targeting users in Korea and globally to deliver malware.
Conducting phishing-email-based malware campaigns against enterprise users, using LNK files to launch obfuscated PowerShell, establish persistence, deploy remote access tools, and steal credentials, screenshots, and keylogging data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.