Also known as: tracked as, Thoreau's flower moth, solar insolation, glandular trichomes
Larva‑24009 is a financially motivated threat actor that has been active since at least 2023, targeting a broad array of industries including healthcare, maritime, financial services, defense and hospitality. The group primarily employs spear‑phishing emails containing malicious LNK files disguised as legitimate documents such as hospital surveys or blockchain proposals; when users click the shortcut, an obfuscated PowerShell script runs that downloads further payloads from command-and-control (C&C) servers. The actor establishes a foothold by creating scheduled‑task persistence and a local privileged account named "_BootUEFI_", facilitating both persistence and lateral movement through RDP. Remote access trojans—most notably QuasarRAT and UltraVNC—are installed to provide full control, screenshot capture, keylogging and credential harvesting using bundled NirSoft tools. Larva‑24009 demonstrates living‑off‑the‑land behavior with MSBuild.exe abuse and exploitation of the CVE‑2017‑11882 Equation Editor vulnerability for privilege escalation. The actor also weaponises trusted cloud platforms (Vercel, GitHub and Dropbox) to host malicious payloads, and embeds a Telegram API interface inside its Notifier malware for stealthy C&C reporting. The campaign’s longevity, repeatable procedures and evolving toolsets signal a well‑established threat actor with sophisticated social engineering and post‑exploitation capabilities, focused on financial gain through credential theft, lateral movement and data exfiltration.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Larva‑24009, also called Thoreau’s flower moth and HeptaX, runs a multi-year financial‑gain campaign that uses spear‑phishing with malicious LNK attachments to deliver obfuscated PowerShell backdoors. The actor establishes persistence via scheduled tasks and privileged accounts, then deploys QuasarRAT or UltraVNC for remote control while harvesting credentials through NirSoft utilities. Its operations span healthcare, maritime, finance, defense and hospitality organizations across South Korea, Australia, Russia and Brazil.
Goals & Targeting
Larva‑24009 seeks to monetize compromised systems by stealing credentials, capturing sensitive data through keylogging and screen capturing, and leveraging stolen accounts for persistent remote access. Its sector‑agnostic approach targets industries that routinely handle large volumes of confidential or financial information, with a noted emphasis on South Korean organizations but also extending globally to countries such as Australia, Russia and Brazil.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first appearance in 2023, Larva‑24009 has maintained a high operational tempo characterized by large-scale spear‑phishing campaigns that combine social engineering with advanced malware delivery chains. The group prefers legitimate cloud hosting for drop points, which makes detection more difficult, and it routinely updates toolsets—shifting from older RATs like njRAT to newer ones such as QuasarRAT—to evade defenses. Victims are drawn from diverse industries and geographies, often accessed through public-facing email infrastructures, while the actor leverages living‑off‑the‑land techniques (MSBuild.exe, Equation Editor exploit) for persistence and privilege escalation.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Evidence for Larva‑24009’s tactics and tools is strong, drawn from multiple threat reports that describe identical LNK phishing vectors, PowerShell backdoor chains, and the use of QuasarRAT/UltraVNC. The actor’s operational timeline (2023–2026) and targeting breadth are well documented. However, gaps remain regarding precise attribution (unknown nation state or threat group affiliation), the full range of command‑and‑control infrastructure, and detailed data exfiltration techniques. Continued monitoring of newly surfaced indicators will help refine these uncertainties.
No campaigns linked yet.
No observed data linked yet.
11
Techniques
46
Tools
0
Campaigns
38
IOCs
0
Observed Data
8
Tactics