Hansom is ransomware associated with intrusion activity attributed to the Larva-26005 cluster, a threat actor assessed by ASEC as likely linked to North Korea and showing tradecraft similarities to Lazarus and Andariel operations. Hansom has been observed in campaigns connected to earlier CRAT activity and later Xctdoor intrusions, indicating its use within a broader multi-malware ecosystem rather than as a standalone criminal commodity.
Historical reporting tied related operations to spear-phishing campaigns targeting South Korean users, including malicious document and shortcut-based lures, as well as trojanized software masquerading as legitimate applications. In linked intrusion chains, operators also abused compromised web servers, web shells, and vulnerable enterprise applications to gain access and deploy follow-on tooling. Cisco Talos reporting referenced in the available facts indicates Hansom was used to encrypt infected systems in at least some of these operations.
The malware’s primary role is file encryption for impact, and its operational context suggests deployment after initial compromise by other malware families such as CRAT or Xctdoor. The campaigns associated with Hansom have targeted Windows environments and have shown a particular focus on South Korean users and organizations. Available information in this dataset does not support more granular technical characterization of Hansom’s internal mechanisms beyond its ransomware function and its association with Larva-26005-linked attack chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Xctdoor와 과거 CRAT 공격 사례의 연관성 분석 (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cisco Talos의 보고서에 따르면 Hansom 랜섬웨어를 설치해 감염 시스템을 암호화하였는데 국내 ASD 로그에서도 동일한 유형의 공격 사례가 확인되었다.
"Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware mentioned in connection with the broader attack cluster/tags in the referenced post.
Named ransomware mentioned in the reference alongside Xctdoor, CRAT, and Larva-26005.
감염 시스템을 암호화하는 랜섬웨어로, 본문에서는 CRAT 및 Xctdoor 초기 버전과 함께 사용된 사례가 설명된다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.