Also known as: APT28, Lophelia pertusa, Fancy Bear, MuddyWater, tracked as, APT29, Madrepora oculata Linnaeus, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Golden Chickens, Venom Spider, Famous Chollima, Wagemole, CVE-2026-46817, LabubaRAT, APT-C-20, hydropower sectors in India, Southeast Asia, Void Dokkaebi, UNC1549, aviation, telecommunications, SHADOW-WATER-063, software developers, corporate recruiters, academic educat, Secret Blizzard, CVE-2026-31431, algif_aead crypto path, with public technical details, proof-of-concept code now available, Earth Centaur, Sapphire Sleet, Silver Fox, Void Arachne, Asia, Mustang Panda, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, SilverFox, Kimsuky, Pawn Storm, Boggy Serpens, Muddy Water, Camaro Dragon, Sednit, APT36, Temp Zagros, Static Kitten, Fishing Elephant, Bloody Wolf, Spring Dragon, UNC5267, Nickel Tapestry, Storm-1877, WaterPlum, PurpleBravo, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, Lotus Blossom, PIRATE PANDA, KeyBoy, Tropic Trooper, BRONZE HOBART, G0081, Red Orthrus, Golden Chickens02, Golden Chickens 02, Pirate Panda, KeyBoys
Larva‑26009 is a sophisticated threat actor that exploits Microsoft SQL Server installations to inject XMRig miners and unauthorized VPN back‑doors. In addition to cryptomining, the group launches endpoint and network level Denial‑of‑Service attacks against DNS, web services, and internal infrastructure. Their approach relies heavily on polymorphic code, software packing, and command obfuscation, allowing them to alter their runtime footprint on every execution. The actor also exploits known vulnerabilities in remote services for lateral movement, hijacks Windows service binaries to establish persistence, and deploys malicious cloud or container images that remain unnoticed until they execute. Email‑cloud account creation is a key component of their operation model, enabling command and control as well as credential acquisition. Strategic operations reveal a focus on rapid discovery through port scanning, vulnerability assessment, and wordlist enumeration. By blending legitimate traffic patterns with malicious activity, Larva‑26009 keeps its network footprint below traditional signature‑based detection thresholds while continuously harvesting cryptocurrency profits.
Southeast Asia
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Larva‑26009 actively targets Microsoft SQL servers to deploy XMRig cryptomining utilities and clandestine VPN services while conducting network‑wide denial‑of‑service attacks. The actor leverages polymorphic code, cloud persistence, and forged browser/systems attributes to evade detection and maintain access, primarily for financial gain.
Goals & Targeting
The primary motivation of Larva‑26009 appears to be financial gain through cryptomining, with secondary goals of establishing footholds for future data exfiltration or sabotage. Their targeting profile spans a wide array of sectors—financial services, government, defense, media, telecommunications, healthcare, utilities, and mining—including both public and private entities across multiple geographies (US, EU, China, India, Iran, Russia). The group demonstrates opportunistic behavior: after gaining an initial foothold, they aggressively expand via remote services exploitation, cloud persistence, and network reconnaissance to sustain long‑term operations. While their operations lack a clear ideological narrative, the systematic deployment of cryptomining payloads indicates a pragmatic approach driven by monetary incentives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Larva‑26009 has repeatedly leveraged Microsoft SQL Server environments as a launchpad for cryptomining, often layering VPN services to obscure traffic origins. The campaign pattern demonstrates a high operational tempo: initial reconnaissance via port and vulnerability scans leads quickly to credential discovery with wordlist attacks, then to persistence through malicious cloud images or hijacked Windows services. The group’s willingness to launch DoS against DNS and web layers illustrates a broader goal of disrupting targeted networks and diverting defensive focus. By maintaining a presence on multiple platforms—on-premises SQL servers, cloud containers, and remote email accounts—the actor ensures sustained operation even if one vector is identified or blocked. Past operations suggest a proclivity for targeting critical infrastructure (utilities, defense), yet the actor also strikes smaller entities like media companies, hinting at opportunistic selection based on vulnerability profiles rather than high‑profile targets alone.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information compiled from multiple slices indicates a moderate to high level of confidence regarding the actor’s technical capabilities, financial motivation, and target profile. Some uncertainties remain around precise attribution (e.g., confirmation that all observed behaviors belong solely to Larva‑26009) and operational timelines (first/last seen dates are not publicly available). Additionally, evidence linking certain tactics such as cloud persistence or VPN deployment may derive from a small set of incidents. Overall, the data supports actionable defensive measures, but continual intelligence updates are recommended.
No campaigns linked yet.
No observed data linked yet.
43
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics