AhnLab Security intelligence Center (ASEC) reported that the Larva-26005 threat actor is actively distributing the Xctdoor malware to users in South Korea and has tied the activity to earlier CRAT attack cases. The report connects the current campaign to malware previously disclosed by ASEC in 2024, indicating continuity in tooling and operations rather than an isolated incident.
The activity also aligns with a separate March 2026 case disclosed by Hauri, where the malware was disguised as an integrated security program to lure victims into infection. The combined reporting suggests an ongoing social-engineering-driven malware campaign in South Korea in which Xctdoor is being reused or adapted alongside tactics seen in prior CRAT-related intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
ASEC reported that Larva-26005 continued targeting South Korean users in April, June, and July 2026 using malicious LNK files. The LNK lures displayed decoy documents while launching the same multi-stage downloader chain used in the earlier fake security software attacks.
Hauri disclosed an attack case in March 2026 involving Xctdoor. In that case, the malware was disguised as an integrated security program.
ASEC had previously disclosed the Xctdoor malware on its blog in 2024, establishing earlier public reporting on the malware family later tied to Larva-26005 activity.
ASEC confirmed that the Larva-26005 threat actor is distributing Xctdoor malware and targeting users in South Korea. The reporting links the current activity to past CRAT-related attack cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcebsky.app
Open sourcemalware.news
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourcehauri.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.