Also known as: tracked as, striped racer, was listed as, apaakozigan in Ojibwemowin, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, enabling host profiling, keylogging, unauthorized file transfer, Germany in addition, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
Larva-26005 emerged in the early 2020s as a sophisticated North‑Korean threat actor that initially delivered the Xctdoor backdoor via spear‑phishing links disguised as standard office documents. The malware is written in C++ and Go, uses DLL side-loading from system32 folders, and deploys multiple script-based droppers—including PowerShell, batch files, and rundll32—to seed its code into AppX package paths where it hides its persistence mechanisms. The actor’s toolset extends beyond Xctdoor. It also includes the older CRAT family (a remote administration trojan) and an evolving cryptominer that targets Microsoft SQL Server installations, deploying as a VPN service for lateral movement and exfiltration of data to cloud storage solutions such as Dropbox, OneDrive, and AWS S3. Operationally, Larva‑26005 relies heavily on compromised email or cloud accounts to deliver phishing payloads, abusing popular web services (Google, GitHub, Twitter) for stealthy command‑and‑control traffic. The malware captures credentials via keylogging and screenshot capture, performs automated data collection (clipboard data, audio capture), and exfiltrates through HTTPS to these cloud endpoints. The actor’s campaigns consistently demonstrate a pattern of using legitimate services and infrastructure to avoid detection, while deploying UAC bypass techniques for privilege escalation and leveraging DLL side‑loading for persistence. The combination of remote access capabilities, cryptomining, and command‑and‑control via public cloud platforms highlights a mature, multi‑phase intrusiveness that aligns with the overall strategic posture expected from a state‑sponsored threat actor.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Larva-26005 is a North‑Korean threat actor that has been active since at least 2020, primarily targeting Korean corporate and governmental organizations. The group uses spear‑phishing LNK attachments, DLL side‑loading, and script‑based droppers to deploy the Xctdoor backdoor and earlier CRAT malware, which provide full remote access, credential theft, and cryptomining capabilities on Microsoft SQL Server installations. Recent campaigns extend beyond South Korea to include South China Sea allies (DE, BR), exploiting compromised email/cloud accounts for initial access and leveraging popular web services as covert command‑and‑control channels.
Goals & Targeting
Larva-26005 primarily aims to acquire political and economic leverage through espionage, disruption, and destructive capabilities. The actor targets defense, government, media, financial services, non-profit, and IT sectors across South Korea, North Korea, Germany, and Brazil, with a clear focus on institutions that provide strategic intelligence, technological data, or financial assets. Their approach combines targeted phishing with social engineering, leveraging compromised email accounts to reach high‑value users, and exploiting publicly available cloud resources for both C2 communications and exfiltration, thereby maximizing operational security while broadening the adversary’s attack surface.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The known operations of Larva‑26005 exhibit a consistent operational cadence, typically launching between late 2020 and early 2023. Their campaigns leverage spear‑phishing LNKs, DLL side‑loading, and script-based droppers to infect target networks. Victim types range from defense contractors and government ministries in South Korea to media outlets, financial firms, non-profits, and IT service providers in Germany and Brazil. A notable past operation includes a high‑profile intrusion into several Korean financial institutions where the actor deployed Xctdoor alongside CRAT modules, extracted credentials, and exfiltrated data to encrypted Dropbox drives. The actor’s patterns also suggest cross‑regional activity linking operations in North Korea with those in neighboring regions through common cloud infrastructure utilization.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the available information is medium-high, as it is based on multiple sources that consistently report on Larva-26005’s tactics and observed malware families. However, gaps exist regarding precise engagement timelines, full scope of targeted sectors beyond those mentioned, and definitive attribution evidence linking all observed variants to a single North‑Korean state-sponsored group. Future work should focus on expanding IOC databases and corroborating cloud‑service-based C2 indicators across different regions.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
43
Tools
0
Campaigns
39
IOCs
0
Observed Data
13
Tactics