Larva-25012: A 2026 Proxyware Distribution Campaign by the Threat Actor (DigitalPulse, SOAX, Appsalt, IPRoyal)

Larva-25012: A 2026 Proxyware Distribution Campaign by the Threat Actor (DigitalPulse, SOAX, Appsalt, IPRoyal)
ASEC reports that Larva-25012 resumed distributing Proxyware in the second half of 2026 by exploiting already infected systems, with recent cases involving DigitalPulse, SOAX, Appsalt, and IPRoyal. The campaign uses DPLoader, PowerShell downloaders, scheduled tasks, and loader/DLL sideloading to install Proxyware and disable defenses on systems in Korea. #Larva-25012 #DPLoader #DigitalPulse #SOAX #Appsalt #IPRoyal #V3

Keypoints

  • Larva-25012 resumed active Proxyware distribution in the second half of 2026, focusing on systems already infected with DPLoader.
  • The group previously spread Proxyware through free YouTube download sites, GitHub masquerading as a Steam cleanup tool, and illegal software/crack pages.
  • DPLoader exists in JavaScript and Python versions, with the JavaScript variant used in most observed attacks to keep execution persistent.
  • PowerShell downloaders are used to fetch and install Proxyware, often by registering scheduled tasks and executing remote scripts.
  • Observed Proxyware families include DigitalPulse, SOAX, Appsalt, and IPRoyal, with some using obfuscation, process injection, or SDK/DLL loader chains.
  • Some attacks attempt to disable Microsoft Defender and use deceptive task names and installation paths to avoid detection.
  • ASEC notes that many systems in Korea have become targets and recommends caution with suspicious downloads and use of V3 products on infected systems.

MITRE Techniques

  • [T1053.005] Scheduled Task – The malware registers itself for persistence and repeated execution through Task Scheduler (‘registered it in the Task Scheduler’, ‘registers the downloaded Proxyware as a task named “PlutonAgentScheduler”’).
  • [T1059.001] PowerShell – PowerShell is used to download and execute payloads and commands (‘PowerShell commands downloaded were of the type that install Proxyware’, ‘iwr -UseBasicParsing -Uri … | iex’).
  • [T1059.003] Windows Command Shell – cmd.exe launches PowerShell to execute the downloader chain (‘Cmd.Exe /d /s /c “PowerShell.Exe …’).
  • [T1105] Ingress Tool Transfer – Remote scripts and components are retrieved from attacker-controlled URLs (‘downloaded via these commands installs Proxyware’, ‘iwr -UseBasicParsing -Uri … | iex’).
  • [T1027] Obfuscated Files or Information – DPLoader is described as obfuscated, and DigitalPulse uses obfuscation to evade detection (‘the obfuscated JavaScript—i.e., DPLoader’, ’employed techniques such as obfuscation’).
  • [T1218.011] System Binary Proxy Execution: Rundll32/Similar Living-off-the-Land Execution via Script Hosts – The campaign uses trusted scripting utilities and Windows components to execute malicious content (‘PowerShell.Exe -ExecutionPolicy Bypass’, ‘Cmd.Exe /d /s /c’).
  • [T1562.001] Impair Defenses – The PowerShell script performs actions to disable Microsoft Defender (‘performs command execution to disable Microsoft Defender’).
  • [T1036] Masquerading – Payloads and tasks are disguised as legitimate software or system services (‘disguising it as a Steam client cleanup tool’, ‘task named “SecurityHealthServiceSyncUpdate”’).
  • [T1106] Native API – The loader calls SDK initialization functions with a threat actor token (‘passes the threat actor’s token as an argument’, ‘calls the appsalt_init() function’).
  • [T1055] Process Injection – DigitalPulse is noted as using injection into Explorer to bypass detection (‘injection into the Explorer process’).

Indicators of Compromise

  • [Domain/URL] PowerShell downloader and C&C/reporting endpoints – hxxp://pub-43fc211373d547278dd3d5bd0b4d9dac.R2[.]Dev/87648736456384.Ps1, https[:]//7jb7qi6vnr5pa22a4br4irz3tu0yqzbd[.]lambda-url[.]us-east-1[.]on[.]aws/e
  • [Domain/URL] Additional script delivery locations – hxxp://dhrciu5akloar.Cloudfront[.]Net/63563545600333.Ps1, hxxp://d6nue5fz4t6y8.Cloudfront[.]Net/9083743654554665.Ps1
  • [Domain/URL] IPRoyal script source – hxxp://dci6j1p0q6khn.Cloudfront[.]Net/784365567456345.Ps1, https[:]//d3mz24vhl6xvgp[.]cloudfront[.]net/CopilotService[.]exe
  • [File path] DigitalPulse installation path – %SystemRoot%plutonplutonagent.Exe, %ProgramFiles%deephourdeephour.Exe
  • [File path] SOAX-related loader and DLL paths – %ProgramFiles%microsoftcopilotservicescopilotservice.Exe, %ProgramFiles%microsoftcopilotservicesliblivenet_amd64.Dll
  • [File path] Appsalt installation paths – %ProgramFiles%microsoftservicingsecurityhealthservicesyncupdate.Exe, %ProgramFiles%microsoftservicingappsalt.Dll
  • [File path] IPRoyal installation paths – %ProgramFiles%MicrosoftTaskRegistrationMaintenanceTaskTaskRegistrationMaintenance.Exe, %ProgramFiles%MicrosoftTaskRegistrationMaintenanceTaskpawns-sdk.DLL
  • [MD5 hash] Sample hashes listed in the report – 0066422310c880d5e722ba59ad315df1, 10498a91dcb16561e32487a47b9832f7, and 3 more hashes
  • [Detection names] V3 detections for downloader/loader/proxyware activity – Downloader/PowerShell.Proxyware.SC316575, Trojan/Win.Loader.C5946067, and other 8 items


Read more: https://asec.ahnlab.com/en/95516/