Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Larva-26009

Also known as: APT28, Lophelia pertusa, Fancy Bear, MuddyWater, tracked as, APT29, Madrepora oculata Linnaeus, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Golden Chickens, Venom Spider, Famous Chollima, Wagemole, CVE-2026-46817, LabubaRAT, APT-C-20, hydropower sectors in India, Southeast Asia, Void Dokkaebi, UNC1549, aviation, telecommunications, SHADOW-WATER-063, software developers, corporate recruiters, academic educat, Secret Blizzard, CVE-2026-31431, algif_aead crypto path, with public technical details, proof-of-concept code now available, Earth Centaur, Sapphire Sleet, Silver Fox, Void Arachne, Asia, Mustang Panda, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, SilverFox, Kimsuky, Pawn Storm, Boggy Serpens, Muddy Water, Camaro Dragon, Sednit, APT36, Temp Zagros, Static Kitten, Fishing Elephant, Bloody Wolf, Spring Dragon, UNC5267, Nickel Tapestry, Storm-1877, WaterPlum, PurpleBravo, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, Lotus Blossom, PIRATE PANDA, KeyBoy, Tropic Trooper, BRONZE HOBART, G0081, Red Orthrus, Golden Chickens02, Golden Chickens 02, Pirate Panda, KeyBoys

Description

Larva‑26009 is a sophisticated threat actor that exploits Microsoft SQL Server installations to inject XMRig miners and unauthorized VPN back‑doors. In addition to cryptomining, the group launches endpoint and network level Denial‑of‑Service attacks against DNS, web services, and internal infrastructure. Their approach relies heavily on polymorphic code, software packing, and command obfuscation, allowing them to alter their runtime footprint on every execution. The actor also exploits known vulnerabilities in remote services for lateral movement, hijacks Windows service binaries to establish persistence, and deploys malicious cloud or container images that remain unnoticed until they execute. Email‑cloud account creation is a key component of their operation model, enabling command and control as well as credential acquisition. Strategic operations reveal a focus on rapid discovery through port scanning, vulnerability assessment, and wordlist enumeration. By blending legitimate traffic patterns with malicious activity, Larva‑26009 keeps its network footprint below traditional signature‑based detection thresholds while continuously harvesting cryptocurrency profits.

TTP Summary

Southeast Asia

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Media
Telecommunications
Healthcare
Utilities
Transportation
Education
Manufacturing
Information technology
Mining
Energy
Hospitality
Non profit
Aviation
Gaming
Construction
Maritime

Targeted Countries / Regions

CN
IN
IR
JP
AE
BR
KR
UA
TW
KP
IL
US
PK
RU
FR
VN
SG
MX
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 14 hours ago

Executive Summary

Larva‑26009 actively targets Microsoft SQL servers to deploy XMRig cryptomining utilities and clandestine VPN services while conducting network‑wide denial‑of‑service attacks. The actor leverages polymorphic code, cloud persistence, and forged browser/systems attributes to evade detection and maintain access, primarily for financial gain.

Goals & Targeting

The primary motivation of Larva‑26009 appears to be financial gain through cryptomining, with secondary goals of establishing footholds for future data exfiltration or sabotage. Their targeting profile spans a wide array of sectors—financial services, government, defense, media, telecommunications, healthcare, utilities, and mining—including both public and private entities across multiple geographies (US, EU, China, India, Iran, Russia). The group demonstrates opportunistic behavior: after gaining an initial foothold, they aggressively expand via remote services exploitation, cloud persistence, and network reconnaissance to sustain long‑term operations. While their operations lack a clear ideological narrative, the systematic deployment of cryptomining payloads indicates a pragmatic approach driven by monetary incentives.

Enhanced Description

Key Capabilities

  • Deploy secondary payloads via mshta.exe
  • Target MS‑SQL servers to install XMRig crypto miners and VPN services
  • Execute DoS attacks against endpoints, networks, DNS, and web services
  • Exploit software vulnerabilities for crash or persistence
  • Hijack Windows service binaries for execution
  • Implement malicious cloud/container images for persistence
  • Create email/cloud provider accounts to support operations
  • Spoof browser and system attributes to blend with legitimate traffic
  • Enumerate network services via port scanning
  • Perform vulnerability scans to identify exploitable software
  • Conduct wordlist credential discovery
  • Use polymorphic/mutating code, packing, command obfuscation, encrypted/encoded payloads

MITRE ATT&CK Tactics

Execution
Persistence
Discovery
Defense Evasion
Credential Access
Impact

ATT&CK Techniques

T1010
T1037
T1046
T1059
T1059.003
T1071
T1087
T1092
T1098
T1110
T1115
T1119
T1123
T1185
T1197
T1499
T1526
T1531
T1538
T1543
T1547
T1554
T1555
T1557
T1595
T1609
T1612
T1613
T1619
T1650
T1651
T1659
T1671
T1134
T1136
T1580
T1583
T1584
T1586

Software / Tooling

XMRig

Campaigns & Victims

Larva‑26009 has repeatedly leveraged Microsoft SQL Server environments as a launchpad for cryptomining, often layering VPN services to obscure traffic origins. The campaign pattern demonstrates a high operational tempo: initial reconnaissance via port and vulnerability scans leads quickly to credential discovery with wordlist attacks, then to persistence through malicious cloud images or hijacked Windows services. The group’s willingness to launch DoS against DNS and web layers illustrates a broader goal of disrupting targeted networks and diverting defensive focus. By maintaining a presence on multiple platforms—on-premises SQL servers, cloud containers, and remote email accounts—the actor ensures sustained operation even if one vector is identified or blocked. Past operations suggest a proclivity for targeting critical infrastructure (utilities, defense), yet the actor also strikes smaller entities like media companies, hinting at opportunistic selection based on vulnerability profiles rather than high‑profile targets alone.

IOC Patterns

  • Outbound HTTP/HTTPS connections from mshta.exe
  • XMRig miner process running on MS‑SQL servers
  • Denial‑of‑Service traffic aimed at DNS and web services
  • Malicious cloud/container images used for persistence
  • Creation of public email accounts (e.g., Gmail, Yahoo) for command & control
  • Polymorphic or mutating executable footprint changes
  • Packed/compressed binaries disguising malicious payloads
  • Obfuscated command strings in scripts
  • Encrypted/encoded payload delivery

Recommended Actions

  • Enforce multi‑factor authentication on all critical services including email, Exchange, and cloud accounts.
  • Monitor and block unauthorized outbound traffic from mshta.exe; maintain whitelists for legitimate usage.
  • Implement rate‑limiting and network monitoring to detect and mitigate DoS attempts.
  • Deploy IDS/IPS signatures targeting port scanning, vulnerability enumeration, and wordlist credential discovery.
  • Leverage behavioral analytics platforms to detect runtime changes indicative of polymorphic malware.
  • Configure anti‑virus engines with heuristic and behavior‑based detection rather than relying solely on static signatures.
  • Apply security patches promptly and restrict privileged access; lock down the ability to hijack service binaries.

Suggested Tags

cryptomining
denial_of_service
ms_sql_server
xmrig
microsoft_mshta
polymorphic_malware
service_discovery
network_reconnaissance
command_obfuscation
encrypted_payloads

Confidence Assessment

The information compiled from multiple slices indicates a moderate to high level of confidence regarding the actor’s technical capabilities, financial motivation, and target profile. Some uncertainties remain around precise attribution (e.g., confirmation that all observed behaviors belong solely to Larva‑26009) and operational timelines (first/last seen dates are not publicly available). Additionally, evidence linking certain tactics such as cloud persistence or VPN deployment may derive from a small set of incidents. Overall, the data supports actionable defensive measures, but continual intelligence updates are recommended.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.wokb.cz — Cited by web research for: APT28
  2. attack.mitre.org — Cited by web research for: services
  3. attack.mitre.org — Cited by web research for: Process Hollowing
  4. https://www.broadcom.com/support/security-center/protection-bulletin/ms-sql-servers-targeted-by-larva-26009-to-deploy-cryptominers-and-vpns — Cited by AI analysis.

Intel Summary

43

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

cryptomining
denial_of_service
ms_sql_server
xmrig
microsoft_mshta
polymorphic_malware
service_discovery
network_reconnaissance
command_obfuscation
encrypted_payloads

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
Aug 7, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.