Xctdoor is a Windows backdoor associated with campaigns targeting South Korean users and organizations, and has been linked to activity tracked as Larva-26005. Reporting connects its operations to earlier CRAT intrusion sets and to tradecraft assessed as consistent with North Korea-aligned operators, with some analyses noting similarities to Lazarus and Andariel activity. Recent campaigns have focused on information theft and sustained remote access rather than confirmed ransomware deployment, although earlier related intrusions reportedly involved Hansom ransomware alongside CRAT and early Xctdoor usage.
Xctdoor has been observed delivered through social engineering and masquerading, including fake security-software installers and malicious shortcut-file lures. Infection chains commonly use DLL sideloading through legitimate executables, followed by script-based download stages and deployment of an auxiliary loader often referred to as XcLoader. That loader decrypts and injects Xctdoor into legitimate processes, enabling stealthier execution and helping evade detection. Both C++ and Go variants have been reported, with equivalent command functionality.
The malware provides full backdoor control of infected systems. Documented capabilities include system information collection, remote command execution, file and folder operations, upload and download of additional payloads, process enumeration and termination, keylogging, screenshot capture, clipboard monitoring, and monitoring of user-idle or session-lock conditions for reporting to command-and-control infrastructure. Xctdoor also supports downloading and executing additional malware, making it suitable as a post-compromise access platform.
Observed campaigns have also used persistence mechanisms such as startup shortcuts, scheduled execution, and loader execution via legitimate Windows utilities. Xctdoor and related components have been noted using runtime code obfuscation and string decryption to hinder analysis. Beyond phishing-style delivery, related intrusions have included web-shell-enabled compromises of Windows IIS servers, abuse of vulnerable groupware upload functionality, and tampering with software distribution or update workflows, indicating that operators use Xctdoor across both user-execution and supply-chain-style intrusion paths.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
31 distinct techniques documented for this family, organized by ATT&CK tactic.
또 다른 사례에서는 외부에 노출되어 있던 그룹웨어 시스템의 업로드 페이지를 통해 초기 침투를 시도한 것으로 추정된다. 취약한 파일 업로드 페이지를 이용해 공격자는 웹셸을 업로드했으며 그룹웨어 시스템에 대한 초기 제어권을 확보하였다.
사용자의 신뢰를 확보한 뒤, 시스템 감염 및 추가 악성 행위를 수행하는 지능형 공격 기법을 사용한다. ... 사용자에 의한 직접 실행 유도 (사회공학 기법 활용)
“{random}.bat”은 다운로더 기능을 수행함과 동시에 동일 경로에 위치한 VBS 다운로더 악성코드 “%PUBLIC%\videos\p{random}.vbs”를 작업 스케줄러에 등록한다.
최종적으로 XCTDoor 악성코드가 실행되며, 다음과 같은 기능을 수행한다. ... 원격 명령 실행 (RCE)
“s{random}.vbs”는 동일 경로에 위치한 BAT 다운로더 악성코드 “%PUBLIC%\videos\{random}.bat”를 실행한다.
오픈 소스 메신저인 BeeBEEP의 설치 파일을 변조하여 Xctdoor를 생성 및 실행하는 루틴을 삽입하였으며 그룹웨어에 존재하는 기존의 설치 파일을 악성 설치 파일로 교체하여 내부 전파하였다는 점이다.
국내 은행 및 공공기관 웹사이트 이용 시 필수적으로 설치가 요구되는 통합 보안 프로그램으로 위장한 악성코드 유포 사례가 확인되었다. ... 정상 소프트웨어 파일명 및 아이콘 모방
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware discussed as a primary subject in an AhnLab analysis connecting Xctdoor to past CRAT attack cases.
Named malware discussed as a primary subject in an analysis of links between Xctdoor and past CRAT attack cases.
A backdoor malware family distributed by the Larva-26005 threat actor and observed targeting users in Korea, including delivery disguised as an integrated security program.
국내 사용자를 표적으로 한 백도어로, C++ 및 Go 변종이 있으며 프로세스 인젝션 후 실행된다. C2 명령을 통해 쉘 실행, 파일 업/다운로드, 프로세스 관리, 키로깅, 스크린샷, 시스템 정보 수집, 메모리 인젝션, 설정 변경 등을 수행한다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.