Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Larva-24005

Also known as: Synaptics worm, UTA0352, UTA0355, impersonate European officials, use platforms like Signal, ARCHIPELAGO, Black Banshee, Thallium, Velvet Chollima, APT43

Description

Larva-24005 is a highly adaptive threat actor that operates under multiple aliases, including Synaptics worm and UTA0352/055. The group is presumed to be state-sponsored and conducts espionage aimed at collecting intelligence on individuals linked to North Korean affairs as well as high‑profile academics and government officials worldwide. The campaign employs a layered delivery stack: spear‑phishing emails that impersonate experts, malicious blogs targeting specific individuals, and exploitation of software vulnerabilities—most notably BlueKeep (CVE‑2019‑0708) and the recent NTLM hash disclosure flaw CVE‑2025‑24054—to gain initial access. Post-compromise, they deploy custom malware such as MySpy and RDPWrap for persistence, keyloggers to harvest credentials, and RATs including AppleSeed and Quasar-based xRAT to maintain remote control. Larva-24005 also abuses OAuth 2.0 workflows on platforms like Signal and WhatsApp, leveraging social engineering to capture authorization codes. They have demonstrated capacity to target Android devices through newly discovered mobile malware, and their threat vector expands across South Korea, the United States, Japan, China, and other nations in key sectors such as defense, energy, finance, academia, media and healthcare.

Goals & Targeting

Targeted Sectors

Government
Media
Defense
Education
Telecommunications
Think tank
Healthcare
Non profit
Energy
Financial services
Manufacturing
Transportation
Critical infrastructure
Nuclear
Hospitality

Targeted Countries / Regions

KP
JP
KR
US
CN
RU
UA
TW
IR
PK
ES
DE
NL
PL
GB
FR
RO
IL
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Larva-24005, a North‑Korean threat actor linked to the Kimsuky (Velvet Chollima) group, conducts sophisticated spear‑phishing campaigns that combine social engineering with exploitation of critical CVEs such as BlueKeep and NTLM hash disclosure. The actor targets a wide spectrum of sectors—government, defense, academia, media, finance, healthcare—and employs custom backdoors, keyloggers, and RDPWrap for persistence. Their operations extend beyond South Korea to the U.S., China, Japan and other regions, utilizing messaging platforms (Signal, WhatsApp), OAuth abuse, malicious blogs, and mobile malware to gain initial footholds before escalating privileges and exfiltrating data.

Goals & Targeting

The actor’s strategic objective appears to be broad‑scale intelligence gathering on entities that influence or observe North Korean affairs. By focusing on government agencies, think tanks, academic institutions, retired diplomats, military personnel, and high‑profile journalists across multiple countries, Larva-24005 seeks to harvest policy deliberations, research outputs, diplomatic communications and technical expertise that can inform state policy decisions. Its targeting pattern reflects a nuanced approach: initial compromise through phishing or software exploitation, followed by credential theft and persistent remote control to facilitate ongoing surveillance and exfiltration of sensitive data.

Enhanced Description

Key Capabilities

  • Spear‑phishing via crafted emails impersonating experts
  • Delivery via malicious blogs targeting high‑profile individuals
  • Use of backdoor RATs such as AppleSeed and Quasar‑based xRAT for persistence and remote control
  • Deployment of mobile malware targeting Android devices
  • Exploitation of software vulnerabilities (e.g., VPN update flaw, Facebook Messenger) to install malware
  • Phishing email campaigns targeting Japanese entities
  • Exploitation of NTLM hash disclosure vulnerability CVE‑2025‑24054 via malicious .library-ms files
  • Abuse of Microsoft OAuth 2.0 workflows to obtain authorization codes
  • Social engineering using Signal and WhatsApp
  • Exploitation of RDP vulnerabilities including BlueKeep (CVE‑2019‑0708)
  • Deployment of custom malware MySpy and RDPWrap for persistence
  • Keylogging to capture user input
  • Use of droppers and RDP scanners in multi‑stage attacks
  • Targeted reach across South Korea, the U.S., China, Japan, and other countries

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access

ATT&CK Techniques

T1566.001
T1189
T1190
T1053
T1106
T1021.001
T1056.001
T1068
T1078
T1589
T1598
T1056.003

Software / Tooling

AppleSeed
xRAT (Quasar-based)
Havex RAT
Babyshark
MySpy
RDPWrap
Keyloggers
Droppers
RDP scanners
Crimson
TRANSLATEXT
Lumma Stealer
Matrix
Hook
Black Banshee
Thallium
Velvet Chollima

Campaigns & Victims

Larva-24005’s operational tempo is rapid and multi‑phased. Campaigns typically begin with mass spear‑phishing campaigns that leverage both email spoofing and malicious content delivery via blogs or OS exploitation, followed by credential harvesting and installation of backdoors for persistence. Victims are primarily individuals in sectors critical to national security—government ministries, defense contractors, research institutions, media outlets, and financial firms—often across multiple countries. The group frequently reuses the same adversary tactics and custom malware components, indicating a well‑researched but evolving toolkit that continues to be refined for broader geographic reach. Notable past operations include the Kimsuky/Babyshark attacks on U.S. think tanks, targeted ransomware campaigns via Quasar RAT, and recent exploitation of VPN update flaws to target corporate networks in Japan and China.

IOC Patterns

  • Public email addresses used in spear‑phishing
  • Malicious blog URLs delivering payloads
  • VPN update exploits targeting login interfaces
  • Facebook Messenger malicious attachments
  • Phishing emails with malicious attachments (e.g., .zip, .lzx)
  • Malicious .library-ms files for NTLM hash disclosure
  • Abuse of Microsoft OAuth 2.0 workflows to capture authorization codes
  • Use of Signal and WhatsApp for social engineering
  • Exploitation of CVE‑2025‑24054 NTLM hash disclosure vulnerability
  • Exploitation of CVE‑2019‑0708 BlueKeep

Recommended Actions

  • Deploy advanced email filtering and user training focused on spear‑phishing that impersonates experts
  • Block malicious blog domains and URLs via web filtering and threat intelligence feeds
  • Implement endpoint detection & response capable of detecting AppleSeed, xRAT, and other RAT activity
  • Patch VPN software and messaging platforms promptly to mitigate known exploitation vectors
  • Apply critical patches for CVE‑2025‑24054, CVE‑2019‑0708, and CVE‑2017‑11882 on all systems
  • Enforce multi‑factor authentication for OAuth 2.0 workflows and all remote access services
  • Monitor and block suspicious .library-ms files and other malspam artifacts
  • Harden Remote Desktop configuration by restricting RDP usage and disabling unnecessary services
  • Deploy keylogger detection tools, droplet scanners, and RDPWrap detection methods
  • Maintain updated threat intelligence feeds on known malicious domains and IOC patterns

Suggested Tags

Kimsuky
APT
North Korean threat actor
Spear Phishing
Malicious Blog Delivery
RAT
AppleSeed
xRAT
Android Malware
Facebook Messenger Exploit
VPN Update Exploit
Larva-24005
Phishing
RDP
BlueKeep
NTLM Exploit
OAuth Abuse
Keylogger
Malspam
Signal
WhatsApp
Microsoft Vulnerabilities

Confidence Assessment

The information synthesis is founded on multiple reputable security analyses, providing strong confidence in the attribution to a North‑Korean actor and the delineated tactics/techniques. Uncertainties remain regarding specific operational timelines, precise motivations beyond espionage, and the full extent of internal capabilities, as public disclosures lack exhaustive technical documentation for all custom malware components.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. cert.europa.eu — Cited by web research for: UTA0352
  2. securityaffairs.com — Cited by web research for: ARCHIPELAGO
  3. attack.mitre.org — Cited by web research for: Interception
  4. apt.etda.or.th — Cited by web research for: PowerShell
  5. securityonline.info — Cited by web research for: curl
  6. blog.netmanageit.com — Cited by web research for: opencti.netmanageit.com
  7. https://securelist.com/the-kimsuky-operation-a-north-korean-apt/57915/ — Cited by AI analysis.
  8. https://www.netscout.com/blog/asert/stolen-pencil-campaign-targets-academia — Cited by AI analysis.
  9. https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/ — Cited by AI analysis.
  10. https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/ — Cited by AI analysis.
  11. https://www.zdnet.com/article/north-korean-state-hackers-target-retired-diplomats-and-military-officials/ — Cited by AI analysis.
  12. https://securelist.com/apt-trends-report-q1-2021/101967/ — Cited by AI analysis.
  13. https://blog.malwarebytes.com/threat-analysis/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/ — Cited by AI analysis.
  14. https://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html — Cited by AI analysis.
  15. https://asec.ahnlab.com/en/31089/ — Cited by AI analysis.
  16. https://medium.com/s2wblog/unveil-the-evolution-of-kimsuky-targeting-android-devices-with-newly-discovered-mobile-malware-280dae5a650f — Cited by AI analysis.
  17. https://asec.ahnlab.com/en/47585/ — Cited by AI analysis.
  18. https://therecord.media/north-korea-apt-kimsuky-attacks — Cited by AI analysis.
  19. https://asec.ahnlab.com/en/52970/ — Cited by AI analysis.
  20. https://www.securonix.com/blog/securonix-threat-research-security-advisory-new-deepgosu-attack-campaign/ — Cited by AI analysis.
  21. https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-vpn-update-flaw-to-install-malware/ — Cited by AI analysis.
  22. https://thehackernews.com/2024/05/north-korean-hackers-exploit-facebook.html — Cited by AI analysis.
  23. https://www.securonix.com/blog/analyzing-deepdrive-north-korean-threat-actors-observed-exploiting-trusted-platforms-for-targeted-attacks/ — Cited by AI analysis.
  24. https://asec.ahnlab.com/en/86535/ — Cited by AI analysis.
  25. https://asec.ahnlab.com/en/88132/ — Cited by AI analysis.

Intel Summary

12

Techniques

49

Tools

0

Campaigns

10

IOCs

0

Observed Data

7

Tactics

Tags

Phishing
APT
espionage
academia
Kimsuky
North Korean threat actor
Spear Phishing
Malicious Blog Delivery
RAT
AppleSeed
xRAT
Android Malware
Facebook Messenger Exploit
VPN Update Exploit
Larva-24005
RDP
BlueKeep
NTLM Exploit
OAuth Abuse
Keylogger
Malspam
Signal
WhatsApp
Microsoft Vulnerabilities

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.