Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors larva-24009

Also known as: tracked as, Thoreau's flower moth, solar insolation, glandular trichomes

Description

Larva‑24009 is a financially motivated threat actor that has been active since at least 2023, targeting a broad array of industries including healthcare, maritime, financial services, defense and hospitality. The group primarily employs spear‑phishing emails containing malicious LNK files disguised as legitimate documents such as hospital surveys or blockchain proposals; when users click the shortcut, an obfuscated PowerShell script runs that downloads further payloads from command-and-control (C&C) servers. The actor establishes a foothold by creating scheduled‑task persistence and a local privileged account named "_BootUEFI_", facilitating both persistence and lateral movement through RDP. Remote access trojans—most notably QuasarRAT and UltraVNC—are installed to provide full control, screenshot capture, keylogging and credential harvesting using bundled NirSoft tools. Larva‑24009 demonstrates living‑off‑the‑land behavior with MSBuild.exe abuse and exploitation of the CVE‑2017‑11882 Equation Editor vulnerability for privilege escalation. The actor also weaponises trusted cloud platforms (Vercel, GitHub and Dropbox) to host malicious payloads, and embeds a Telegram API interface inside its Notifier malware for stealthy C&C reporting. The campaign’s longevity, repeatable procedures and evolving toolsets signal a well‑established threat actor with sophisticated social engineering and post‑exploitation capabilities, focused on financial gain through credential theft, lateral movement and data exfiltration.

Goals & Targeting

Targeted Sectors

Healthcare
Maritime
Financial services
Defense
Hospitality

Targeted Countries / Regions

KR
AU
RU
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 4 hours ago

Executive Summary

Larva‑24009, also called Thoreau’s flower moth and HeptaX, runs a multi-year financial‑gain campaign that uses spear‑phishing with malicious LNK attachments to deliver obfuscated PowerShell backdoors. The actor establishes persistence via scheduled tasks and privileged accounts, then deploys QuasarRAT or UltraVNC for remote control while harvesting credentials through NirSoft utilities. Its operations span healthcare, maritime, finance, defense and hospitality organizations across South Korea, Australia, Russia and Brazil.

Goals & Targeting

Larva‑24009 seeks to monetize compromised systems by stealing credentials, capturing sensitive data through keylogging and screen capturing, and leveraging stolen accounts for persistent remote access. Its sector‑agnostic approach targets industries that routinely handle large volumes of confidential or financial information, with a noted emphasis on South Korean organizations but also extending globally to countries such as Australia, Russia and Brazil.

Enhanced Description

Key Capabilities

  • Spear-phishing with malicious LNK attachments
  • Execution via obfuscated PowerShell scripts
  • Persistence through scheduled‑task creation
  • C&C reporting via Telegram API
  • Installation of remote access trojans QuasarRAT and UltraVNC
  • Creation of privileged backdoor accounts (e.g., _BootUEFI_)
  • Exploitation of RDP for lateral movement
  • Data exfiltration with NirSoft tools
  • Screen capturing and keylogging for credential theft

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Command and Control
Remote Services

ATT&CK Techniques

T1566.001
T1059.001
T1027
T1053.005
T1113
T1056.001
T1136.001
T1076
T1223
T1105
T1021.004

Software / Tooling

Notifier malware
QuasarRAT
UltraVNC
NirSoft tools
Custom PowerShell scripts
Batch script(s)
njRAT

Campaigns & Victims

Since its first appearance in 2023, Larva‑24009 has maintained a high operational tempo characterized by large-scale spear‑phishing campaigns that combine social engineering with advanced malware delivery chains. The group prefers legitimate cloud hosting for drop points, which makes detection more difficult, and it routinely updates toolsets—shifting from older RATs like njRAT to newer ones such as QuasarRAT—to evade defenses. Victims are drawn from diverse industries and geographies, often accessed through public-facing email infrastructures, while the actor leverages living‑off‑the‑land techniques (MSBuild.exe, Equation Editor exploit) for persistence and privilege escalation.

IOC Patterns

  • Phishing email attachment with malicious LNK file
  • Obfuscated PowerShell script execution
  • Scheduled-task persistence creation
  • Telegram API-based command and control communications
  • Privileged account creation with suspicious names
  • RDP exploitation for lateral movement
  • NirSoft credential harvesting tools in use
  • Screen capture and keylogging activity

Recommended Actions

  • Block and filter phishing emails that contain malicious LNK attachments.
  • Educate users through spear‑phishing awareness training to recognize unexpected attachment-based threats.
  • Implement monitoring for creation of new scheduled tasks or execution of known obfuscated PowerShell scripts.
  • Detect and alert on the creation of privileged accounts with anomalous names such as "_BootUEFI_".
  • Restrict and secure RDP access, enforce MFA for remote connections.
  • Deploy endpoint detection that identifies QuasarRAT, UltraVNC, njRAT and other RAT families.
  • Block or monitor outbound traffic to Telegram API endpoints used for command and control.
  • Apply least‑privilege principles to limit credential theft via keylogging and screenshot tools.
  • Maintain network segmentation and monitor for suspicious data exfiltration patterns over HTTP/HTTPS or SMB.
  • Use domain and IP reputation services to block known malicious hosting domains.

Suggested Tags

phishing
spearphishing attachment
LNK attack
PowerShell abuse
obfuscated malware
scheduled task persistence
Telegram C&C
QuasarRAT
UltraVNC
backdoor account
RDP exploitation
NirSoft
credential theft
keylogging
screen capture
South Korea target
marine sector
financial services
healthcare industry

Confidence Assessment

Evidence for Larva‑24009’s tactics and tools is strong, drawn from multiple threat reports that describe identical LNK phishing vectors, PowerShell backdoor chains, and the use of QuasarRAT/UltraVNC. The actor’s operational timeline (2023–2026) and targeting breadth are well documented. However, gaps remain regarding precise attribution (unknown nation state or threat group affiliation), the full range of command‑and‑control infrastructure, and detailed data exfiltration techniques. Continued monitoring of newly surfaced indicators will help refine these uncertainties.

ATT&CK Techniques

Command & Control
1 technique
Initial Access
1 technique
Lateral Movement
1 technique
Persistence
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 7 IPv4 Address 1 MD5 Hash 5 Domain 7

References

  1. mallory.ai — Cited by web research for: PowerShell scripts
  2. asec.ahnlab.com — Cited by web research for: Payload
  3. mallory.ai — Cited by web research for: Payload
  4. asec.ahnlab.com — Cited by web research for: njRAT
  5. https://mallory.ai/actors/019fc6f3-a4b2-75c3-b355-2839d3680a0d — Cited by AI analysis.
  6. https://malware.news/t/analysis-of-a-phishing-email-attack-case-by-the-larva-24009-threat-actor/124446 — Cited by AI analysis.
  7. https://x.com/TweetThreatNews/status/2084274362257940631 — Cited by AI analysis.
  8. https://www.linkedin.com/posts/hendryadrian_korea-quasarrat-ultravnc-activity-7490040089062969345-k7C- — Cited by AI analysis.

Intel Summary

11

Techniques

46

Tools

0

Campaigns

38

IOCs

0

Observed Data

8

Tactics

Tags

phishing
spear-phishing
malware delivery via email
LNK
PowerShell
Korea targeting
larva-24009
credential harvesting
remote access trojan
QuasarRAT
UltraVNC
Telegram C&C
keylogging
screen capture
NirSoft tools
backdoor account
social engineering
trojanized installer
proxyjacking
trusted cloud exploitation
living off the land
defense evasion
vulnerability exploitation
exfiltration
spearphishing attachment
LNK attack
PowerShell abuse
obfuscated malware
scheduled task persistence
RDP exploitation
NirSoft
credential theft
South Korea target
marine sector
financial services
healthcare industry

Details

Type
Unknown
Primary Motivation
Financial gain
Confidence
55%
Added
Aug 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.