Also known as: Synaptics worm, UTA0352, UTA0355, impersonate European officials, use platforms like Signal, ARCHIPELAGO, Black Banshee, Thallium, Velvet Chollima, APT43
Larva-24005 is a highly adaptive threat actor that operates under multiple aliases, including Synaptics worm and UTA0352/055. The group is presumed to be state-sponsored and conducts espionage aimed at collecting intelligence on individuals linked to North Korean affairs as well as high‑profile academics and government officials worldwide. The campaign employs a layered delivery stack: spear‑phishing emails that impersonate experts, malicious blogs targeting specific individuals, and exploitation of software vulnerabilities—most notably BlueKeep (CVE‑2019‑0708) and the recent NTLM hash disclosure flaw CVE‑2025‑24054—to gain initial access. Post-compromise, they deploy custom malware such as MySpy and RDPWrap for persistence, keyloggers to harvest credentials, and RATs including AppleSeed and Quasar-based xRAT to maintain remote control. Larva-24005 also abuses OAuth 2.0 workflows on platforms like Signal and WhatsApp, leveraging social engineering to capture authorization codes. They have demonstrated capacity to target Android devices through newly discovered mobile malware, and their threat vector expands across South Korea, the United States, Japan, China, and other nations in key sectors such as defense, energy, finance, academia, media and healthcare.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Larva-24005, a North‑Korean threat actor linked to the Kimsuky (Velvet Chollima) group, conducts sophisticated spear‑phishing campaigns that combine social engineering with exploitation of critical CVEs such as BlueKeep and NTLM hash disclosure. The actor targets a wide spectrum of sectors—government, defense, academia, media, finance, healthcare—and employs custom backdoors, keyloggers, and RDPWrap for persistence. Their operations extend beyond South Korea to the U.S., China, Japan and other regions, utilizing messaging platforms (Signal, WhatsApp), OAuth abuse, malicious blogs, and mobile malware to gain initial footholds before escalating privileges and exfiltrating data.
Goals & Targeting
The actor’s strategic objective appears to be broad‑scale intelligence gathering on entities that influence or observe North Korean affairs. By focusing on government agencies, think tanks, academic institutions, retired diplomats, military personnel, and high‑profile journalists across multiple countries, Larva-24005 seeks to harvest policy deliberations, research outputs, diplomatic communications and technical expertise that can inform state policy decisions. Its targeting pattern reflects a nuanced approach: initial compromise through phishing or software exploitation, followed by credential theft and persistent remote control to facilitate ongoing surveillance and exfiltration of sensitive data.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Larva-24005’s operational tempo is rapid and multi‑phased. Campaigns typically begin with mass spear‑phishing campaigns that leverage both email spoofing and malicious content delivery via blogs or OS exploitation, followed by credential harvesting and installation of backdoors for persistence. Victims are primarily individuals in sectors critical to national security—government ministries, defense contractors, research institutions, media outlets, and financial firms—often across multiple countries. The group frequently reuses the same adversary tactics and custom malware components, indicating a well‑researched but evolving toolkit that continues to be refined for broader geographic reach. Notable past operations include the Kimsuky/Babyshark attacks on U.S. think tanks, targeted ransomware campaigns via Quasar RAT, and recent exploitation of VPN update flaws to target corporate networks in Japan and China.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information synthesis is founded on multiple reputable security analyses, providing strong confidence in the attribution to a North‑Korean actor and the delineated tactics/techniques. Uncertainties remain regarding specific operational timelines, precise motivations beyond espionage, and the full extent of internal capabilities, as public disclosures lack exhaustive technical documentation for all custom malware components.
No campaigns linked yet.
No observed data linked yet.
12
Techniques
49
Tools
0
Campaigns
10
IOCs
0
Observed Data
7
Tactics