Larva-24009 is known for global phishing campaigns targeting Korean users with LNK malware and remote access tools.
Analyst brief
Larva-24009 is a threat actor active since at least 2023, conducting phishing email campaigns globally with a focus on users in Korea. It uses phishing emails with keywords like "hospital survey" and "resume" to deliver LNK malware that installs a PowerShell backdoor, maintaining persistence with remote control tools such as QuasarRAT and UltraVNC. The actor aims to steal sensitive information, including credentials and user files. Defenders should prioritize user awareness training against phishing, enforce controls on LNK file execution, and monitor for anomalous PowerShell commands along with QuasarRAT or UltraVNC network traffic.
Larva-24009
activeunknown
Larva-24009 has been active since at least 2023, conducting phishing email attacks to install malware globally, particularly targeting users in Korea. The actor employs LNK malware to install a PowerShell backdoor and maintains persistence with remote control tools like QuasarRAT and UltraVNC. They utilize phishing emails with keywords such as “hospital survey” and “resume,” disguising malware as document files to trick users into execution. This results in the theft of sensitive information, including credentials and user files.