Larva-26005 is a threat cluster assessed to be linked to North Korea and associated with tradecraft resembling Lazarus and Andariel operations. The actor has targeted users and organizations in South Korea since at least 2020 and is known for deploying the Xctdoor backdoor, as well as earlier CRAT malware activity that in some cases overlapped with Hansom ransomware intrusions. Recent operations appear primarily focused on information theft and persistent access rather than confirmed ransomware deployment. Larva-26005 has used multiple initial-access vectors, including spear-phishing with malicious LNK files, trojanized software installers masquerading as legitimate South Korean security products, compromise of unmanaged IIS servers, exploitation of vulnerable groupware file-upload functionality to deploy web shells, and tampering with enterprise software update mechanisms including Korean ERP solutions. The actor has also used DLL side-loading to launch loaders and droppers, followed by script-based download chains using VBS, BAT, and PowerShell components. A recurring infection chain involves XcLoader as an intermediate loader and injector. XcLoader decrypts and injects Xctdoor into legitimate processes and is used together with persistence mechanisms such as startup shortcuts and Regsvr32-based execution. Across observed campaigns, the actor has shown consistent use of runtime code obfuscation and deobfuscation, AppX-style installation paths, and process injection into benign Windows processes. Xctdoor has been observed in both C++ and Go implementations with broadly equivalent functionality. The malware provides extensive post-compromise capability, including shell command execution, file transfer and deletion, process enumeration and termination, system information collection, clipboard monitoring, screenshot capture, keylogging, and user-idle monitoring based on session or display state. Historical CRAT activity attributed to the same cluster also included reconnaissance, file operations, command execution, payload download, persistence, and exfiltration. Known aliases and related labels directly supported here are limited to Larva-26005. The cluster has been assessed as likely connected to North Korean state-aligned activity, with operational similarities to Lazarus and Andariel.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster discussed in connection with Xctdoor and past CRAT attack cases, with phishing and LNK-themed indicators referenced in the post.
A named activity cluster discussed in connection with analysis of links between Xctdoor and past CRAT attack cases.
Distributing the Xctdoor malware to users in South Korea, including attacks where the malware was disguised as an integrated security program.
South Korea-focused intrusion cluster active since at least 2020, distributing Xctdoor and XcLoader via spear-phishing LNK files, trojanized security software installers, compromised web servers, groupware upload pages, and patched ERP software. Earlier activity linked CRAT, Xctdoor, and Hansom ransomware together; more recent activity appears focused on backdoor deployment and information collection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.