Also known as: tracked as, Bladabindi, the Newscaster Team, High-Boiling Fraction CASRN, Ratenjay
The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the installer from the VPN website, malware can be installed on the system. Since at least 2023, the Larva-24010 threat actor has been targeting Korean VPN users to spread malware, ultimately installing various backdoors such as MeshAgent, gs-netcat, and NKNShell. Through this, the attacker can control infected systems where the VPN is installed and steal sensitive information stored on those systems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Larva-24010 is a threat actor actively distributing malware through a compromised Korean VPN service provider's website, exploiting user trust in legitimate software downloads. Since 2023, the group has targeted Korean users by installing backdoors such as MeshAgent, gs-netcat, and NKNShell, enabling remote system control and data exfiltration. This campaign highlights a strategic focus on compromising trusted infrastructure to gain persistent access to victims' systems.
Goals & Targeting
Larva-24010's strategic objectives appear to center on espionage and persistent access to systems within South Korea, leveraging the compromisedVPN service to target users who rely on the provider for secure connectivity. By exploiting the trusted infrastructure of aVPN provider, the actor likely seeks to infiltrate both individual users and organizations, potentially targeting sectors such as finance, technology, and government institutions that depend heavily on secure remote communications. The focus on Korean victims suggests a regional interest, possibly tied to geopolitical motives or the acquisition of sensitive data from users within the country.
Enhanced Description
The Larva-24010 threat actor leverages the compromised website of a Korean VPN service provider to distribute malware disguised as legitimate installer software. Once users download and execute the malicious installer, backdoors such as MeshAgent and NKNShell are deployed, granting the actor remote administrative access to infected systems. This method exploits users' trust in theVPN provider, bypassing traditional security measures. The actor's operations have been ongoing since at least 2023, targeting individuals and organizations using the infectedVPN service. The deployed malware enables persistent access, data exfiltration, and potential lateral movement within affected networks. This approach underscores a focus on supply chain compromises and the use of trusted digital infrastructures to evade detection and maintain long-term access to victim environments.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Larva-24010's campaigns since 2023 have consistently targeted Korean users through a compromisedVPN service provider, demonstrating a focus on supply chain attacks and the exploitation of trusted digital infrastructures. The actor's operational tempo suggests a sustained effort to maintain access and expand reach within the region, potentially leveraging theVPN's user base to infiltrate both individual and organizational networks. Notably, the use of backdoors like MeshAgent and NKNShell indicates an emphasis on long-term, stealthy operations rather than short-term disruptions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides moderate confidence in the actor's methods and targeting based on observed activities since 2023 and the use of compromised infrastructure. However, gaps exist regarding the actor's full operational scope, potential links to other groups, and motivations beyond the targeting of KoreanVPN users. Additional intelligence is required to confirm the presence of other campaigns or the association of Larva-24010 with known threat groups.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
41
Tools
0
Campaigns
39
IOCs
0
Observed Data
0
Tactics