Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors larva-26005

Also known as: tracked as, striped racer, was listed as, apaakozigan in Ojibwemowin, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, enabling host profiling, keylogging, unauthorized file transfer, Germany in addition, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

Larva-26005 emerged in the early 2020s as a sophisticated North‑Korean threat actor that initially delivered the Xctdoor backdoor via spear‑phishing links disguised as standard office documents. The malware is written in C++ and Go, uses DLL side-loading from system32 folders, and deploys multiple script-based droppers—including PowerShell, batch files, and rundll32—to seed its code into AppX package paths where it hides its persistence mechanisms. The actor’s toolset extends beyond Xctdoor. It also includes the older CRAT family (a remote administration trojan) and an evolving cryptominer that targets Microsoft SQL Server installations, deploying as a VPN service for lateral movement and exfiltration of data to cloud storage solutions such as Dropbox, OneDrive, and AWS S3. Operationally, Larva‑26005 relies heavily on compromised email or cloud accounts to deliver phishing payloads, abusing popular web services (Google, GitHub, Twitter) for stealthy command‑and‑control traffic. The malware captures credentials via keylogging and screenshot capture, performs automated data collection (clipboard data, audio capture), and exfiltrates through HTTPS to these cloud endpoints. The actor’s campaigns consistently demonstrate a pattern of using legitimate services and infrastructure to avoid detection, while deploying UAC bypass techniques for privilege escalation and leveraging DLL side‑loading for persistence. The combination of remote access capabilities, cryptomining, and command‑and‑control via public cloud platforms highlights a mature, multi‑phase intrusiveness that aligns with the overall strategic posture expected from a state‑sponsored threat actor.

Goals & Targeting

Targeted Sectors

Defense
Media
Financial services
Government
Non profit
Information technology

Targeted Countries / Regions

KR
KP
DE
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Larva-26005 is a North‑Korean threat actor that has been active since at least 2020, primarily targeting Korean corporate and governmental organizations. The group uses spear‑phishing LNK attachments, DLL side‑loading, and script‑based droppers to deploy the Xctdoor backdoor and earlier CRAT malware, which provide full remote access, credential theft, and cryptomining capabilities on Microsoft SQL Server installations. Recent campaigns extend beyond South Korea to include South China Sea allies (DE, BR), exploiting compromised email/cloud accounts for initial access and leveraging popular web services as covert command‑and‑control channels.

Goals & Targeting

Larva-26005 primarily aims to acquire political and economic leverage through espionage, disruption, and destructive capabilities. The actor targets defense, government, media, financial services, non-profit, and IT sectors across South Korea, North Korea, Germany, and Brazil, with a clear focus on institutions that provide strategic intelligence, technological data, or financial assets. Their approach combines targeted phishing with social engineering, leveraging compromised email accounts to reach high‑value users, and exploiting publicly available cloud resources for both C2 communications and exfiltration, thereby maximizing operational security while broadening the adversary’s attack surface.

Enhanced Description

Key Capabilities

  • Bypasses User Account Control (UAC) for privilege escalation
  • Compromises email and cloud accounts for initial access and credential theft
  • Uses common web services (Google, GitHub, Twitter, Dropbox, OneDrive, AWS) as covert command‑and‑control channels
  • Deploys cryptomining malware on Microsoft SQL Server installations
  • Establishes VPN services to facilitate remote lateral movement
  • Targets and exploits MS‑SQL databases for persistence and mining
  • Performs DLL side‑loading and script‑based dropping of payloads
  • Captures screenshots, keylogs, and audio for data theft
  • Exfiltrates data via cloud storage solutions

MITRE ATT&CK Tactics

Privilege Escalation
Credential Access
Initial Access
Command And Control
Exfiltration

ATT&CK Techniques

T1037
T1557
T1583
T1613
T1123
T1547
T1566.001
T1119
T1115
T1071
T1659
T1010
T1560
T1185
T1580
T1217
T1092
T1595
T1548
T1087
T1059
T1020
T1609
T1584
T1612
T1586
T1619
T1204
T1554
T1098
T1110
T1531
T1671
T1197
T1650
T1651
T1134
T1136
T1526
T1538

Software / Tooling

Xctdoor
CRAT
Larva-26005

Campaigns & Victims

The known operations of Larva‑26005 exhibit a consistent operational cadence, typically launching between late 2020 and early 2023. Their campaigns leverage spear‑phishing LNKs, DLL side‑loading, and script-based droppers to infect target networks. Victim types range from defense contractors and government ministries in South Korea to media outlets, financial firms, non-profits, and IT service providers in Germany and Brazil. A notable past operation includes a high‑profile intrusion into several Korean financial institutions where the actor deployed Xctdoor alongside CRAT modules, extracted credentials, and exfiltrated data to encrypted Dropbox drives. The actor’s patterns also suggest cross‑regional activity linking operations in North Korea with those in neighboring regions through common cloud infrastructure utilization.

IOC Patterns

  • Use of legitimate web services for command‑and‑control
  • Exfiltration via cloud storage (Dropbox, OneDrive, AWS S3)
  • Compromise and reuse of email accounts for phishing campaigns
  • Bypassing UAC mechanisms for privilege escalation

Recommended Actions

  • Implement privileged access management and monitor for UAC bypass attempts
  • Detect outbound traffic to popular web service APIs used for C2 and exfiltration
  • Deploy monitoring for anomalous usage or compromise of corporate cloud and email accounts
  • Enforce least‑privilege principles on local account creation and usage
  • Apply security patches for Microsoft SQL Server promptly
  • Monitor logs for anomalous VPN connections and remote access attempts
  • Deploy detection rules to flag cryptomining activity on servers
  • Isolate affected servers from the network until remediation is complete

Suggested Tags

Xctdoor
CRAT
Larva-26005
UAC bypass
Web services abuse
Cloud storage exfiltration
Compromised email
Command And Control via Web Service
Cryptomining
VPN setup
MS‑SQL
South Korea
North Korea

Confidence Assessment

The confidence in the available information is medium-high, as it is based on multiple sources that consistently report on Larva-26005’s tactics and observed malware families. However, gaps exist regarding precise engagement timelines, full scope of targeted sectors beyond those mentioned, and definitive attribution evidence linking all observed variants to a single North‑Korean state-sponsored group. Future work should focus on expanding IOC databases and corroborating cloud‑service-based C2 indicators across different regions.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. mallory.ai — Cited by web research for: enabling host profiling
  3. attack.mitre.org — Cited by web research for: Process Hollowing
  4. https://www.broadcom.com/support/security-center/protection-bulletin/ms-sql-servers-targeted-by-larva-26009-to-deploy-cryptominers-and-vpns — Cited by AI analysis.

Intel Summary

40

Techniques

43

Tools

0

Campaigns

39

IOCs

0

Observed Data

13

Tactics

Tags

Xctdoor
CRAT
Larva-26005
UAC bypass
Web services abuse
Cloud storage exfiltration
Compromised email
Command And Control via Web Service
Cryptomining
VPN setup
MS‑SQL
South Korea
North Korea

Details

Type
Unknown
Primary Motivation
Ideology
Country of Origin
Germany (DE)
Confidence
55%
Added
Aug 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.