Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Analysis of a Phishing Email Attack Case

4ad28d0313549e98383144d82982be6e

TLP:CLEAR
Active

MD5 Hash

Description

The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Analysis of a Phishing Email Attack Case
Pattern Type
STIX
Confidence
75%
Valid From
Aug 4, 2026 10:00
Total Sightings
0
Added
Aug 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 4ad28d0313549e98383144d82982be6e

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.