Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)

Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
AhnLab SEcurity intelligence Center linked Larva-26005 to Xctdoor campaigns in Korea, including 2026 attacks disguised as Veraport and SoftCamp installers and LNK-based phishing cases that delivered XcLoader and Xctdoor. The report also connects these operations to earlier CRAT activity, Hansom ransomware, Ngrok, and Lazarus-related tradecraft, while listing related IOCs such as hesenorm[.]info and several MD5 hashes. #Xctdoor #XcLoader #CRAT #Hansom #Larva26005 #Lazarus

Keypoints

  • ASEC confirmed that Larva-26005 is distributing Xctdoor to users in Korea.
  • 2026 attacks used droppers disguised as Veraport and SoftCamp installers, with DLL side-loading to launch malicious components.
  • The attack chain created script files in %PUBLIC%videos and used BAT/VBS/PowerShell stages to download XcLoader and Xctdoor.
  • LNK-based attacks continued through 2026, often appearing as spear phishing and targeting both general and corporate users.
  • ASEC also identified 2024 cases where XcLoader and Xctdoor were deployed after compromising IIS servers, groupware upload pages, and a Korean ERP solution.
  • Xctdoor supports extensive backdoor functions including shell commands, file operations, screenshots, keylogging, process control, and configuration changes.
  • ASec connected the activity to older CRAT campaigns, Hansom ransomware cases, and Lazarus-related infrastructure and tradecraft.

MITRE Techniques

  • [T1574.002 ] DLL Side-Loading – The malware was executed by loading malicious DLLs alongside legitimate executables (‘it uses DLL side-loading to load and execute a malicious dropper named “credui.Dll”‘)
  • [T1059.005 ] Visual Basic – VBS scripts were created and executed as part of the infection chain (‘VBS launcher malware “%PUBLIC%videoss{random}.Vbs” is executed’)
  • [T1059.003 ] Windows Command Shell – BAT files were used as downloaders and command execution was performed through cmd.exe (‘” {Random}.Bat” performs its downloader function’; ‘multiple command execution (using cmd /c)’)
  • [T1059.001 ] PowerShell – A PowerShell script moved, decoded, and launched payloads (‘PowerShell script “%PUBLIC%videos2.Ps1″‘; ‘XOR-decodes the “l{random}” file’)
  • [T1027 ] Obfuscated Files or Information – Multiple malware components encrypted or obfuscated their code and decrypted it at runtime (‘the code section is decrypted during execution’)
  • [T1105 ] Ingress Tool Transfer – The malware downloaded Xctdoor, XcLoader, and a PowerShell launcher from remote URLs (‘downloads XcLoader and Xctdoor’)
  • [T1547.001 ] Registry Run Keys / Startup Folder – Persistence was maintained by creating a shortcut on the startup path and using Run key behavior (‘creates and executes a shortcut on the startup path to maintain persistence’)
  • [T1053.005 ] Scheduled Task/Job – A VBS downloader was registered in Task Scheduler (‘registering the VBS downloader malware … in the Task Scheduler’)
  • [T1021.001 ] Remote Services: Remote Desktop Protocol – The backdoor executed commands and managed sessions over its C2 channel, including shell sessions (‘Create shell session object’)
  • [T1055 ] Process Injection – XcLoader injected Xctdoor into legitimate processes such as explorer.exe (‘the decoded roaming.Dat PE file is injected into that process’)
  • [T1218.010 ] System Binary Proxy Execution: Regsvr32 – Regsvr32 was used to run the loader malware (‘uses the RegSvr32 process via a LNK file’)
  • [T1106 ] Native API – The malware created processes, loaded DLLs, and performed low-level execution flow control through Windows APIs (‘CreateProcess’, ‘ShellExecute’, ‘RegSvr32’)
  • [T1204.002 ] User Execution: Malicious File – Users were induced to open LNK files, installers, and decoy documents (‘LNK files are used during the Initial Intrusion phase’)
  • [T1566.001 ] Phishing: Spearphishing Attachment – CRAT distribution began with a phishing document exploiting a vulnerability (‘distributed via a spear phishing attack using a Hangul document’)

Indicators of Compromise

  • [MD5 hashes ] Malware or related sample hashes – 01b58f2ff2c14feed46a0768ea46686d, 07766e6e9d9f86775ad564a65af292c1, and 3 more hashes
  • [Domains ] C2/download and related infrastructure – hesenorm[.]info, casinolegit[.]fun, and other 3 domains
  • [URLs ] Download and hosting URLs used for payload delivery or lure content – http[:]//hesenorm[.]Info/download/xtps, http[:]//hesenorm[.]Info/download/lcpy, and other 3 URLs
  • [File names ] Malicious or lure files used in the campaigns – veraport-q3.Exe, SCWSSPSetup.Exe, and other named files such as 2.Ps1 and roaming.Dat
  • [Email addresses ] Ransom note / threat actor contact addresses tied to Hansom – hansom2008@protonmail[.]Com, hansompay2008@yandex[.]Com
  • [Named pipes ] CRAT-related inter-process communication – .PipeChromeUpdatePipe
  • [Windows paths ] Installation, staging, and persistence locations – %PUBLIC%videoss{random}.Vbs, %LOCALAPPDATA%PackagesMicrosoft.MicrosoftOffice365Hub_8wekyb3d8bbweSettingsroaming.Dat


Read more: https://asec.ahnlab.com/en/94847/