Larva-26005 is a North Korea-linked threat actor active since at least 2020 and associated with sustained malware operations targeting users and organizations in South Korea. The actor is known for distributing the Xctdoor backdoor and has been linked to earlier CRAT campaigns, with reporting noting tradecraft overlaps and operational similarities to Lazarus and Andariel-associated activity. Historical intrusions have also involved Hansom ransomware alongside CRAT and early Xctdoor variants, indicating prior use of ransomware-adjacent tooling, although more recent operations appear focused on information theft rather than confirmed encryption activity. Larva-26005 has used multiple initial access vectors, including spear-phishing with LNK-based lures, trojanized software installers, compromised web infrastructure, and abuse of vulnerable enterprise applications. Observed campaigns have disguised malware as legitimate Korean security software, modified collaboration software installers for internal spread, compromised IIS servers with web shells, and tampered with ERP update mechanisms. The actor has also abused DLL side-loading and RegSvr32-based execution chains to launch loaders and maintain persistence. Its tooling includes XcLoader as an intermediate loader and injector, and Xctdoor as the primary backdoor payload. XcLoader decrypts and injects Xctdoor into legitimate processes, while Xctdoor supports broad post-compromise functionality including shell access, file transfer, process control, command execution, keylogging, screenshot capture, shared-memory operations, configuration changes, and host-status monitoring. Reporting also links Larva-26005 to CRAT, a remote access trojan used for reconnaissance, command execution, file operations, payload delivery, persistence, and exfiltration. Across these malware families, analysts have noted recurring use of runtime code obfuscation, AppX-style installation paths, process injection, and persistence through shortcuts and RegSvr32 execution. The actor’s targeting has centered on South Korean victims, including both general users and enterprise environments, with lure themes spanning business, legal, finance, recruiting, security, and software topics. Intrusions against Korean web servers, groupware platforms, and ERP environments indicate a particular interest in organizational networks and information collection. High-confidence reporting assesses Larva-26005 as a North Korea-linked espionage-oriented actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distributing the Xctdoor malware to users in South Korea, including attacks where the malware was disguised as an integrated security program.
Conducting espionage-oriented malware campaigns targeting South Korean users and organizations, distributing Xctdoor and XcLoader via phishing LNK files, fake security software installers, compromised web servers, vulnerable groupware upload pages, and trojanized enterprise software/ERP update mechanisms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.