Larva-24005 is a threat actor breaching South Korean servers for North Korea-focused phishing, exploiting the BlueKeep vulnerability (CVE-2019-0708).
Analyst brief
Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, targeting individuals involved with North Korea and university professors researching the regime. Exploiting the BlueKeep vulnerability for initial access, the actor deploys RDPWrap and a custom keylogger, while phishing emails are crafted to appear legitimate and contain malicious URLs or compressed files. Defenders should focus on detecting traces of phishing pages stored in the IIS_USER account and XAMPP home folder that were later deleted, and ensure the BlueKeep vulnerability (CVE-2019-0708) is patched.
Larva-24005
unknown
Larva-24005 is a threat actor that breaches servers in Korea to establish a web server and PHP environment for phishing attacks, primarily targeting individuals involved with North Korea and university professors researching the regime. They exploit the BlueKeep vulnerability for initial access and utilize RDPWrap and a custom keylogger post-compromise. Phishing emails are crafted to appear as legitimate communications, often containing malicious URLs or compressed files. The actor has been observed storing phishing pages in the IIS_USER account and XAMPP home folder, although traces of these pages were later deleted.