Quick Takeaways
- The Larva-24009 actor primarily uses phishing emails with decoy documents and LNK malware to deploy PowerShell backdoors and malware like QuasarRAT and UltraVNC for remote control and persistence.
- Attackers gather sensitive data using keyloggers, credential stealer tools, and NirSoft utilities, while maintaining persistence through scheduled tasks and malicious scripts.
- They exploit remote access protocols and backdoor accounts to control infected systems, risking data theft and remote system compromise at targeted enterprises globally.
Threat, Techniques, and Targets
The Larva-24009 threat actor has been active since 2023. They mainly launch phishing email attacks targeting users in Korea and around the world. Their goal is to install malware on infected systems. In 2026, they continued similar attacks found in previous years. The attacker uses email with decoy documents, such as project proposals and resumes, to trick users into opening malicious files. They use LNK files that run obfuscated PowerShell commands when opened. These commands create decoy files and download additional malicious scripts from external sources.
Once the malware runs, it installs a PowerShell backdoor. The attacker maintains access by installing remote control tools like QuasarRAT and UltraVNC. They also install screenshot, keylogging, and credential theft tools. The attacker sometimes exploits Remote Desktop Protocol (RDP) and creates backdoor accounts to control infected systems remotely.
Targeted organizations are mainly enterprises across various sectors. The attack methods include using fake documents to lure users into executing malware. The malware uses file names similar to previous campaigns, and the attack involves multiple Command and Control (C&C) URLs that facilitate malware communication.
Impact, Implications, and Guidance
The attacks enable the threat actor to steal sensitive data and gain remote control of infected systems. They can extract user credentials, monitor activities, and capture screenshots. Additionally, they can take control of systems via RAT software or RDP exploits. This compromises not only individual user data but can also threaten entire enterprise networks.
The malware used in these attacks is sophisticated, using multiple tools to maintain persistence and avoid detection. Because of this, organizations should prioritize security updates and patches. Users should be cautious with email attachments and links from unknown sources. It is crucial to scan files before opening and verify sender authenticity.
If an organization encounters a similar attack, they should seek specific remediation guidance from their security vendor or relevant authority. This includes analyzing detected malware, removing infections, and strengthening defenses against future attacks. Proper incident response is essential to minimize damage and restore secure operations.
Discover More Technology Insights
Learn how the Internet of Things (IoT) is transforming everyday life.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
