Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor

Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor
Larva-24009 has continued phishing campaigns since at least 2023, using LNK files to deliver PowerShell backdoors and later deploy tools such as QuasarRAT, UltraVNC, and NirSoft utilities. The 2026 activity shows the same core malware and file-name patterns as earlier cases, with credential theft, screenshots, keylogging, and Telegram-based reporting used to support long-term compromise. #Larva-24009 #QuasarRAT #UltraVNC #Notifier #NirSoft

Keypoints

  • Larva-24009 has been active since at least 2023 and continues phishing-based attacks in 2026.
  • The group targets users in Korea and globally, often aiming at enterprises with decoy documents about hospital surveys, blockchain, proposals, and resumes.
  • LNK files trigger obfuscated PowerShell that drops decoy files, downloads scripts, and launches additional payloads from a C&C server.
  • Persistence is maintained through Task Scheduler entries with masqueraded task names such as “Intel(R) Ethernet3 Connection 1219-LM” and Google Update-style names.
  • The attackers deploy QuasarRAT and UltraVNC Server for remote control, and may also use RDP and a backdoor account named “_BootUEFI_”.
  • Information theft is performed with screenshots, keylogger scripts, and NirSoft tools such as ChromePassView, WebBrowserBookmarksView, Network Password Recovery, and LastActivityView.
  • Notifier version 2.1 uses the Telegram API to send infection status reports to the threat actor instead of relying only on the original C&C channel.

MITRE Techniques

  • [T1566.001 ] Phishing: Spearphishing Attachment – The actor delivers malicious LNK attachments through email to lure victims into execution (‘phishing emails targeting users’).
  • [T1204.002 ] User Execution: Malicious File – The attack depends on the user opening the disguised document shortcut file (‘when the LNK file is executed’).
  • [T1059.001 ] Command and Scripting Interpreter: PowerShell – An obfuscated PowerShell command runs to create a decoy, download scripts, and execute payloads (‘an obfuscated PowerShell command runs’).
  • [T1105 ] Ingress Tool Transfer – Additional scripts and payloads are downloaded from external sources and the C&C server (‘downloading and executing an additional PowerShell script’).
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Persistence is established by registering tasks in Task Scheduler (‘tasks are registered in the Task Scheduler’).
  • [T1105 ] Ingress Tool Transfer – C&C URLs are used to fetch payloads and maintenance scripts (‘Download additional payload’).
  • [T1113 ] Screen Capture – PowerShell scripts are used to take screenshots of the infected system (‘capture screenshots’ and ‘Send Screenshot’).
  • [T1112 ] Modify Registry – Windows Defender is disabled through scripts to reduce detection (‘disabling Windows Defender’).
  • [T1027 ] Obfuscated Files or Information – The initial command is obfuscated to hide malicious behavior (‘an obfuscated PowerShell command’).
  • [T1056.001 ] Keylogging – Keylogger malware is created to capture keystrokes (‘Keylogging data storage path’).
  • [T1056.004 ] Input Capture: Credential API Hooking – Credential theft is supported by tools that recover stored passwords and browser credentials (‘Extracts credentials stored in the Chrome web browser’).
  • [T1070.004 ] File Deletion: File Deletion on Host – Decoy and operational files are created in %TEMP%, suggesting staging and possible cleanup behavior (‘creates a decoy file in the %TEMP% directory’).
  • [T1021.001 ] Remote Services: Remote Desktop Protocol – The report says the actor may also control the system by exploiting RDP (‘it is believed that they also control the infected system by exploiting RDP’).
  • [T1219 ] Remote Access Software – QuasarRAT and UltraVNC are installed for remote control (‘installed Quasar RAT and UltraVNC Server’).

Indicators of Compromise

  • [MD5 hashes ] malware and tool samples identified in the campaign – 10b40185106eb3760cb71c46117aa0bf, 1500fefcdda275b70e2051a3e7d9f794, and 3 more hashes
  • [URLs ] C&C and tool download locations used for payload retrieval and tool staging – http[:]//aonexa[.]shop/candy/res/get-command[.]php, http[:]//final[.]mainsec2[.]site/secsec/tool/ChromePass[.]exe, and 3 more URLs
  • [FQDNs ] domains hosting C&C infrastructure and payloads – aonexa[.]shop, final[.]mainsec2[.]site, and 3 more domains
  • [IP addresses ] server infrastructure associated with the campaign – 217[.]77[.]6[.]50
  • [File names ] LNK decoys and download artifacts used in the attack – NovaCX_Agency_Updated_2026047_091100_version_1_8.Docx.Lnk, NovaCX_Interview_QA+Updated_20260420_162448_version_4_4.Docx.Lnk
  • [Windows task names ] persistence tasks created to disguise the malware – Intel(R) Ethernet3 Connection 1219-LM, GoogleUpdateTaskMachineCoreUA2{F84AE75F-E9CE-4FC0-9BC8-998371F0931}
  • [Account names ] backdoor account created for access – _BootUEFI_
  • [File paths ] keylogger output locations on infected hosts – %ALLUSERSPROFILE%MicrosoftOneDrivelog.Log, %ALLUSERSPROFILE%MicrosoftOneDrivelogv.Log


Read more: https://asec.ahnlab.com/en/94786/