Larva-24009 has continued phishing campaigns since at least 2023, using LNK files to deliver PowerShell backdoors and later deploy tools such as QuasarRAT, UltraVNC, and NirSoft utilities. The 2026 activity shows the same core malware and file-name patterns as earlier cases, with credential theft, screenshots, keylogging, and Telegram-based reporting used to support long-term compromise. #Larva-24009 #QuasarRAT #UltraVNC #Notifier #NirSoft
Keypoints
- Larva-24009 has been active since at least 2023 and continues phishing-based attacks in 2026.
- The group targets users in Korea and globally, often aiming at enterprises with decoy documents about hospital surveys, blockchain, proposals, and resumes.
- LNK files trigger obfuscated PowerShell that drops decoy files, downloads scripts, and launches additional payloads from a C&C server.
- Persistence is maintained through Task Scheduler entries with masqueraded task names such as âIntel(R) Ethernet3 Connection 1219-LMâ and Google Update-style names.
- The attackers deploy QuasarRAT and UltraVNC Server for remote control, and may also use RDP and a backdoor account named â_BootUEFI_â.
- Information theft is performed with screenshots, keylogger scripts, and NirSoft tools such as ChromePassView, WebBrowserBookmarksView, Network Password Recovery, and LastActivityView.
- Notifier version 2.1 uses the Telegram API to send infection status reports to the threat actor instead of relying only on the original C&C channel.
MITRE Techniques
- [T1566.001 ] Phishing: Spearphishing Attachment â The actor delivers malicious LNK attachments through email to lure victims into execution (âphishing emails targeting usersâ).
- [T1204.002 ] User Execution: Malicious File â The attack depends on the user opening the disguised document shortcut file (âwhen the LNK file is executedâ).
- [T1059.001 ] Command and Scripting Interpreter: PowerShell â An obfuscated PowerShell command runs to create a decoy, download scripts, and execute payloads (âan obfuscated PowerShell command runsâ).
- [T1105 ] Ingress Tool Transfer â Additional scripts and payloads are downloaded from external sources and the C&C server (âdownloading and executing an additional PowerShell scriptâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Persistence is established by registering tasks in Task Scheduler (âtasks are registered in the Task Schedulerâ).
- [T1105 ] Ingress Tool Transfer â C&C URLs are used to fetch payloads and maintenance scripts (âDownload additional payloadâ).
- [T1113 ] Screen Capture â PowerShell scripts are used to take screenshots of the infected system (âcapture screenshotsâ and âSend Screenshotâ).
- [T1112 ] Modify Registry â Windows Defender is disabled through scripts to reduce detection (âdisabling Windows Defenderâ).
- [T1027 ] Obfuscated Files or Information â The initial command is obfuscated to hide malicious behavior (âan obfuscated PowerShell commandâ).
- [T1056.001 ] Keylogging â Keylogger malware is created to capture keystrokes (âKeylogging data storage pathâ).
- [T1056.004 ] Input Capture: Credential API Hooking â Credential theft is supported by tools that recover stored passwords and browser credentials (âExtracts credentials stored in the Chrome web browserâ).
- [T1070.004 ] File Deletion: File Deletion on Host â Decoy and operational files are created in %TEMP%, suggesting staging and possible cleanup behavior (âcreates a decoy file in the %TEMP% directoryâ).
- [T1021.001 ] Remote Services: Remote Desktop Protocol â The report says the actor may also control the system by exploiting RDP (âit is believed that they also control the infected system by exploiting RDPâ).
- [T1219 ] Remote Access Software â QuasarRAT and UltraVNC are installed for remote control (âinstalled Quasar RAT and UltraVNC Serverâ).
Indicators of Compromise
- [MD5 hashes ] malware and tool samples identified in the campaign â 10b40185106eb3760cb71c46117aa0bf, 1500fefcdda275b70e2051a3e7d9f794, and 3 more hashes
- [URLs ] C&C and tool download locations used for payload retrieval and tool staging â http[:]//aonexa[.]shop/candy/res/get-command[.]php, http[:]//final[.]mainsec2[.]site/secsec/tool/ChromePass[.]exe, and 3 more URLs
- [FQDNs ] domains hosting C&C infrastructure and payloads â aonexa[.]shop, final[.]mainsec2[.]site, and 3 more domains
- [IP addresses ] server infrastructure associated with the campaign â 217[.]77[.]6[.]50
- [File names ] LNK decoys and download artifacts used in the attack â NovaCX_Agency_Updated_2026047_091100_version_1_8.Docx.Lnk, NovaCX_Interview_QA+Updated_20260420_162448_version_4_4.Docx.Lnk
- [Windows task names ] persistence tasks created to disguise the malware â Intel(R) Ethernet3 Connection 1219-LM, GoogleUpdateTaskMachineCoreUA2{F84AE75F-E9CE-4FC0-9BC8-998371F0931}
- [Account names ] backdoor account created for access â _BootUEFI_
- [File paths ] keylogger output locations on infected hosts â %ALLUSERSPROFILE%MicrosoftOneDrivelog.Log, %ALLUSERSPROFILE%MicrosoftOneDrivelogv.Log
Read more: https://asec.ahnlab.com/en/94786/