Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Larva-24010

Also known as: tracked as, Bladabindi, the Newscaster Team, High-Boiling Fraction CASRN, Ratenjay

Description

The Larva-24010 threat actor is distributing malware through the website of a Korean VPN service provider. As a result, when a user downloads and runs the installer from the VPN website, malware can be installed on the system. Since at least 2023, the Larva-24010 threat actor has been targeting Korean VPN users to spread malware, ultimately installing various backdoors such as MeshAgent, gs-netcat, and NKNShell. Through this, the attacker can control infected systems where the VPN is installed and steal sensitive information stored on those systems.

Goals & Targeting

Targeted Sectors

Chemical
Food agriculture
Energy
Financial services
Government
Oil gas
Manufacturing
Education
Construction
Media
Transportation
Defense
Healthcare
Utilities
Aerospace
Mining

Targeted Countries / Regions

US
MX
CN
BR
EG
JP
TR

AI Analysis

· 1 week ago

Executive Summary

Larva-24010 is a threat actor actively distributing malware through a compromised Korean VPN service provider's website, exploiting user trust in legitimate software downloads. Since 2023, the group has targeted Korean users by installing backdoors such as MeshAgent, gs-netcat, and NKNShell, enabling remote system control and data exfiltration. This campaign highlights a strategic focus on compromising trusted infrastructure to gain persistent access to victims' systems.

Goals & Targeting

Larva-24010's strategic objectives appear to center on espionage and persistent access to systems within South Korea, leveraging the compromisedVPN service to target users who rely on the provider for secure connectivity. By exploiting the trusted infrastructure of aVPN provider, the actor likely seeks to infiltrate both individual users and organizations, potentially targeting sectors such as finance, technology, and government institutions that depend heavily on secure remote communications. The focus on Korean victims suggests a regional interest, possibly tied to geopolitical motives or the acquisition of sensitive data from users within the country.

Enhanced Description

The Larva-24010 threat actor leverages the compromised website of a Korean VPN service provider to distribute malware disguised as legitimate installer software. Once users download and execute the malicious installer, backdoors such as MeshAgent and NKNShell are deployed, granting the actor remote administrative access to infected systems. This method exploits users' trust in theVPN provider, bypassing traditional security measures. The actor's operations have been ongoing since at least 2023, targeting individuals and organizations using the infectedVPN service. The deployed malware enables persistent access, data exfiltration, and potential lateral movement within affected networks. This approach underscores a focus on supply chain compromises and the use of trusted digital infrastructures to evade detection and maintain long-term access to victim environments.

Key Capabilities

  • Malware distribution via compromised legitimate websites
  • Installation of sophisticated backdoors (e.g., MeshAgent, NKNShell)
  • Remote system control and data exfiltration
  • Use of compromised trusted infrastructure to evade detection
  • Persistence mechanisms for long-term access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1109.001
T1059.003
T1040
T1041
T1047
T1057.001
T1105.001

Software / Tooling

MeshAgent
gs-netcat
NKNShell

Campaigns & Victims

Larva-24010's campaigns since 2023 have consistently targeted Korean users through a compromisedVPN service provider, demonstrating a focus on supply chain attacks and the exploitation of trusted digital infrastructures. The actor's operational tempo suggests a sustained effort to maintain access and expand reach within the region, potentially leveraging theVPN's user base to infiltrate both individual and organizational networks. Notably, the use of backdoors like MeshAgent and NKNShell indicates an emphasis on long-term, stealthy operations rather than short-term disruptions.

IOC Patterns

  • Malware distribution via compromised legitimate websites
  • Backdoor installation through installer binaries
  • C2 communication using domain-based channels
  • Staged infrastructure on trusted provider's servers

Recommended Actions

  • Monitor for unauthorized software installers downloaded from third-party websites
  • Verify digital signatures of executables and installer packages
  • Implement network segmentation to limit lateral movement
  • Block unexpected outbound traffic to known C2 domains
  • Deploy endpoint detection and response (EDR) tools to detect backdoor activity
  • Conduct user training on secure software installation practices and phishing awareness

Suggested Tags

APT
Espionage
South Korea
Backdoor
Supply Chain Attack

Confidence Assessment

The available data provides moderate confidence in the actor's methods and targeting based on observed activities since 2023 and the use of compromised infrastructure. However, gaps exist regarding the actor's full operational scope, potential links to other groups, and motivations beyond the targeting of KoreanVPN users. Additional intelligence is required to confirm the presence of other campaigns or the association of Larva-24010 with known threat groups.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 8 MD5 Hash 5 Filename 7

References

  1. nepis.epa.gov — Cited by web research for: High-Boiling Fraction CASRN
  2. asec.ahnlab.com — Cited by web research for: MESHAGENT
  3. attack.mitre.org — Cited by web research for: Interception
  4. ctid.mitre.org — Cited by web research for: Explorer

Intel Summary

0

Techniques

41

Tools

0

Campaigns

39

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT
Espionage
South Korea
Backdoor
Supply Chain Attack

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.