Security researchers reported ongoing phishing activity by Larva-24009, a threat actor active since at least 2023, using email lures to compromise users and install malware. The campaign has targeted victims in South Korea as well as organizations and users internationally, with analysis published by AhnLab ASEC and echoed by other researchers including Cyble.
The newly documented case adds to earlier disclosures from 2024 that linked the actor to similar email-based intrusion activity, indicating a sustained malware delivery operation rather than an isolated incident. Public reporting attributes the attacks to phishing emails crafted to trick recipients into opening malicious content, reinforcing the continued risk from socially engineered initial access campaigns aimed at broad regional and cross-border targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
ASEC describes the 2026 intrusion chain as using obfuscated PowerShell, scheduled-task persistence, Notifier malware including a Telegram-reporting variant, QuasarRAT, UltraVNC Server, likely RDP access, NirSoft theft tools, and a batch script that creates a backdoor account named '_BootUEFI_.'.
ASEC says Larva-24009 was still conducting attacks in 2026, primarily using phishing emails with LNK files disguised as documents to target enterprise users in Korea and globally.
The references state that ASEC previously disclosed attack cases attributed to Larva-24009 in 2024. The newer campaign's malware and file naming patterns are described as broadly consistent with that earlier activity.
ASEC reports that the Larva-24009 threat actor has been active since at least 2023, conducting phishing email attacks to install malware on targets in South Korea and other countries.
Cyble is said to have identified the same phishing campaign and named it HeptaX, linking its findings to the activity attributed by ASEC to Larva-24009.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.