Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Larva‑25012

Also known as: tracked as, the, the Newscaster Team, the euechinoids, into the blastocoel, the primary mesenchyme cells, McClay, 1985, the secondary mesenchyme cells, SMCs, Ettensohn, 1996, FLRFamide, PMCs

Description

Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows Explorer process and employs Python-based loaders to evade detection. They distribute Proxyware installers primarily through advertisements on websites offering free YouTube video downloads and fake sites for cracked software. Larva‑25012 has been active since at least 2024, distributing multiple types of Proxyware, including DigitalPulse, Honeygain, and Infatica.

Goals & Targeting

Targeted Sectors

Education
Financial services
Aviation
Government
Telecommunications
Manufacturing
Defense
Food agriculture
Mining
Transportation

Targeted Countries / Regions

GB
US

AI Analysis

· 1 week ago

Executive Summary

Larva-25012 is an unidentified threat actor known for deploying Proxyware through malicious Notepad++ installers. They inject Proxyware into the Windows Explorer process, use Python-based loaders to evade detection, and distribute their payloads via advertisements on websites offering free YouTube video downloads or fake cracked software. The actor has been active since at least 2024, targeting users in an unspecified manner with multiple types of Proxyware.

Goals & Targeting

The strategic objectives of Larva-25012 remain unclear due to limited available intelligence. However, their use of Proxyware suggests a focus on establishing long-term control over targeted systems for potential surveillance or data theft. Their targeting appears to be indiscriminate, as they distribute malware through general-interest websites, preying on users seeking free content or software cracks. This broad targeting indicates that Larva-25012 is likely not limited to specific sectors or regions.

Enhanced Description

Larva-25012 is a relatively unknown threat actor that focuses on deploying Proxyware, which enables unauthorized control over infected systems. Their primary method involves creating malicious installers disguised as Notepad++, a popular text editing software, to distribute their payloads. Once executed, the malware injects itself into the Windows Explorer process to maintain persistence and avoid detection. Additionally, Larva-25012 employs Python-based loaders to further evade detection mechanisms, making their campaigns more sophisticated than typical commodity malware. The actor's distribution methods include targeting users through advertisements on websites offering free YouTube video downloads or fake sites for cracked software, which are common vectors for phishing and malvertising campaigns. Since first being observed in 2024, Larva-25012 has been linked to multiple Proxyware variants, including DigitalPulse, Honeygain, and Infatica.

Key Capabilities

  • Proxyware deployment
  • Notepad++ installer disguise
  • Windows process injection
  • Python-based loader usage

MITRE ATT&CK Tactics

Reconnaissance
Exfiltration

ATT&CK Techniques

T1059
T1566

Software / Tooling

DigitalPulse
Honeygain
Infatica
Notepad++ (malicious installer)

Campaigns & Victims

Larva-25012 has been active since at least 2024, with campaigns focusing on distributing Proxyware through malicious advertisements. Their targeting appears to be broad, with a focus on users visiting websites offering free YouTube video downloads or cracked software. Despite their activity since 2024, there is limited information about specific campaigns, victimology, or the geographic scope of their operations.

IOC Patterns

  • Spear-phishing campaigns via malicious advertisements
  • Payload delivered via Notepad++ installer
  • Windows process injection into explorer.exe

Recommended Actions

  • Enhance network monitoring to detect suspicious processes and outbound communications from infected systems.
  • Educate users on the risks of downloading software from untrusted sources or engaging with pop-up ads on questionable websites.
  • Implement endpoint detection and response (EDR) solutions to identify and block malicious Python-based loaders and process injection activities.

Suggested Tags

APT
Proxyware
Malvertising

Confidence Assessment

Low confidence in the available data due to limited public reporting on Larva-25012. Key gaps include specific campaign details, targeting patterns, and the full scope of their toolkit. Further analysis is required to fully understand their operational capabilities and objectives.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. pmc.ncbi.nlm.nih.gov — Cited by web research for: the euechinoids
  2. axaemarchives.utah.gov — Cited by web research for: Mosquito

Intel Summary

3

Techniques

41

Tools

0

Campaigns

22

IOCs

0

Observed Data

1

Tactics

Tags

APT
Proxyware
Malvertising

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.