Also known as: tracked as, the, the Newscaster Team, the euechinoids, into the blastocoel, the primary mesenchyme cells, McClay, 1985, the secondary mesenchyme cells, SMCs, Ettensohn, 1996, FLRFamide, PMCs
Larva‑25012 is a threat actor known for deploying Proxyware, utilizing malware disguised as a Notepad++ installer. The actor injects Proxyware into the Windows Explorer process and employs Python-based loaders to evade detection. They distribute Proxyware installers primarily through advertisements on websites offering free YouTube video downloads and fake sites for cracked software. Larva‑25012 has been active since at least 2024, distributing multiple types of Proxyware, including DigitalPulse, Honeygain, and Infatica.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Larva-25012 is an unidentified threat actor known for deploying Proxyware through malicious Notepad++ installers. They inject Proxyware into the Windows Explorer process, use Python-based loaders to evade detection, and distribute their payloads via advertisements on websites offering free YouTube video downloads or fake cracked software. The actor has been active since at least 2024, targeting users in an unspecified manner with multiple types of Proxyware.
Goals & Targeting
The strategic objectives of Larva-25012 remain unclear due to limited available intelligence. However, their use of Proxyware suggests a focus on establishing long-term control over targeted systems for potential surveillance or data theft. Their targeting appears to be indiscriminate, as they distribute malware through general-interest websites, preying on users seeking free content or software cracks. This broad targeting indicates that Larva-25012 is likely not limited to specific sectors or regions.
Enhanced Description
Larva-25012 is a relatively unknown threat actor that focuses on deploying Proxyware, which enables unauthorized control over infected systems. Their primary method involves creating malicious installers disguised as Notepad++, a popular text editing software, to distribute their payloads. Once executed, the malware injects itself into the Windows Explorer process to maintain persistence and avoid detection. Additionally, Larva-25012 employs Python-based loaders to further evade detection mechanisms, making their campaigns more sophisticated than typical commodity malware. The actor's distribution methods include targeting users through advertisements on websites offering free YouTube video downloads or fake sites for cracked software, which are common vectors for phishing and malvertising campaigns. Since first being observed in 2024, Larva-25012 has been linked to multiple Proxyware variants, including DigitalPulse, Honeygain, and Infatica.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Larva-25012 has been active since at least 2024, with campaigns focusing on distributing Proxyware through malicious advertisements. Their targeting appears to be broad, with a focus on users visiting websites offering free YouTube video downloads or cracked software. Despite their activity since 2024, there is limited information about specific campaigns, victimology, or the geographic scope of their operations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in the available data due to limited public reporting on Larva-25012. Key gaps include specific campaign details, targeting patterns, and the full scope of their toolkit. Further analysis is required to fully understand their operational capabilities and objectives.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
41
Tools
0
Campaigns
22
IOCs
0
Observed Data
1
Tactics